Developer docs
API playgroundTry for free, no card

Search company profiles

Veracode

Full company profile

uuid0000n93

Namestring
Veracode
Legal namestring
Veracode, Inc.
Websiteurl
veracode.com
Company typeenum
Private
Founded yearint
2006
Descriptiontext

Veracode, Inc. is a privately held application security company founded in 2006 and headquartered in Burlington, Massachusetts, that sells a cloud-based Application Risk Management Platform to enterprise and mid-market organizations. The platform unifies multiple testing modalities — Static Analysis (SAST), Dynamic Analysis (DAST), Software Composition Analysis (SCA), Container Security, and External Attack Surface Management — alongside proprietary modules: Veracode Risk Manager (an ASPM solution built from the April 2024 Longbow Security acquisition), Veracode Fix (an AI-powered code remediation tool patented in April 2025), and Veracode Package Firewall (which identifies 40–50 indicators of compromise to block malicious open-source packages across NPM, PyPI, Maven, Nexus, Artifactory, and Azure Artifacts). The platform is built on a proprietary vulnerability database accumulated over two decades of scanning, currently covering 1.5M+ applications, 135M+ flaws fixed, and 448T+ lines of code, supporting a sub-1.1% false-positive rate. The product integrates deeply into developer and security workflows via IDE plugins (Eclipse, IntelliJ, VS Code, Visual Studio), CI/CD (Jenkins, Azure DevOps), SCM (GitHub, GitLab), ticketing (Jira, Bugzilla), ITSM/GRC (ServiceNow, RSA Archer), and WAF tools (Imperva, ModSecurity), and participates in the Wiz Integration Network for cloud security correlation.

Veracode generates revenue primarily through annual subscription contracts with quote-based pricing for enterprise and mid-market customers, distributed via a sales-led motion that combines direct field sales for large enterprises, inside sales for mid-market, and the Velocity Partner Program for channel distribution (with regional distributors such as AmiViz for MEA and Centrico/Sella for Italian banking). The company serves a diverse customer base spanning financial services, government/public sector, healthcare, retail/e-commerce, energy, and developers/DevSecOps teams, with named enterprise customers including HDI Global SE, Manhattan Associates, Cox Automotive, Azalea Health, and Tecnimont Services (MAIRE). The firm holds FedRAMP and StateRAMP authorizations that unlock U.S. federal, state, and local government contracts, and operates engineering offices in Prague (opened 2023 with Accion Labs) in addition to its Burlington headquarters and London EMEA office. It is backed by TA Associates following a March 2022 growth investment, has completed three acquisitions in roughly two years (Crashtest Security, Longbow Security, Phylum), and is led by CEO Brian Roche, appointed in April 2024, alongside a refreshed executive team including a new CFO, Chief Strategy Officer, and General Counsel added during 2025.

Short descriptiontext

Veracode is a private application security company founded in 2006 that sells a cloud-based Application Risk Management Platform combining SAST, DAST, SCA, container security, ASPM, AI-powered remediation, and supply chain protection to enterprise and mid-market customers across regulated industries and government.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
501–1,000
akta.pro rankint
HeadquartersBurlington, United States
HQ citystring
Burlington
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices3 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
application security testing, software composition analysis, application risk management, static code analysis, software supply chain security
Industry2 codes
1Application Security Testing (SAST/DAST/IAST/SCA)
CodeHDADACACPrimaryYes
2Code & Repository Security (Git Security, Code Integrity)
CodeHDADACAGPrimaryNo
NAICS code1 code
  • Software Publishers5132
SIC code1 code
  • Services-Prepackaged Software7372
Product category
Application Security Testing
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Application Security Platform Subscription
TypeSubscription Recurring
Description

Veracode generates revenue primarily through subscription-based licensing of its Application Risk Management Platform. Customers pay for access to security scanning tools including SAST, DAST, SCA, and AI-powered remediation capabilities.

veracode.com
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Pricing details1 tier
1Enterprise and mid-market subscription tiers with quote-based pricing
ModelSubscriptionBilling cadenceAnnual
Notes

Pricing not publicly disclosed; requires contacting sales for quotes. Annual contracts typical for enterprise deployments.

veracode.com
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 3 records shown
1Veracode Risk Manager
Description

An Application Security Posture Management (ASPM) platform that provides unified visibility and remediation of application risk. Originally developed from the Longbow Security acquisition.

veracode.com
+2 more records
Core offering1 text field

Veracode provides a cloud-based Application Risk Management Platform that identifies security risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform combines SAST, DAST, SCA, container security, a package firewall, ASPM (Risk Manager), and AI-powered remediation (Veracode Fix), sold primarily as annual subscriptions to enterprise and mid-market organizations.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 6 values shown
  • 184% ROI for Veracode Application Risk Management Platform customers (Total Economic Impact Study)
+5 more records
Product overview1 text field

Veracode offers a unified Application Risk Management platform designed for the AI-coding era. The portfolio centers on the Veracode Platform providing AI-driven prioritization and integrated tools to detect, understand, and remediate application vulnerabilities across the SDLC. Core testing products include SAST (Static Analysis) for source code scanning, DAST (Dynamic Analysis) for runtime web app testing, SCA (Software Composition Analysis) for open-source vulnerabilities, and Container Security for container technologies. The platform is enhanced by Veracode Fix (AI-powered code remediation that automates vulnerability fixes through pull requests), Veracode Package Firewall (supply chain protection blocking malicious packages from NPM, PyPI, Maven, Azure Artifacts, Nexus, and Artifactory), and Veracode Risk Manager (ASPM providing unified visibility and risk correlation). Additional modules include eLearning and Security Labs for developer training, PTaaS for penetration testing services, Application Security Consulting, Pipeline Scan for CI/CD integration, and External Attack Surface Management for discovering internet-exposed assets. The platform integrates with IDEs (Eclipse, IntelliJ, Visual Studio, VS Code), CI/CD tools (Jenkins, Azure DevOps), SCM systems (GitHub, GitLab), ticketing platforms (Jira, Bugzilla), and security/WAF tools (Imperva, ModSecurity). Veracode has grown through acquisitions including Longbow Security (now Risk Manager), Phylum (malicious package detection), and Crashtest Security (DAST capability).

Product and service12 records
1Veracode Platform
CategoryApplication Security Platform
Description

Unified Application Risk Management platform combining SAST, DAST, SCA, container security, package firewall, AI remediation, and ASPM for enterprise application security programs.

2SAST (Static Application Security Testing)
CategoryApplication Security Testing
Description

Static Application Security Testing product that scans source and binary code to find vulnerabilities during development for enterprise development teams.

3DAST (Dynamic Application Security Testing)
CategoryApplication Security Testing
Description

Dynamic Application Security Testing product that finds and fixes runtime vulnerabilities in running web applications, including AI-assisted authentication and EASM capabilities.

4SCA (Software Composition Analysis)
CategorySoftware Composition Analysis
Description

Software Composition Analysis product that identifies vulnerable and malicious open-source components and license compliance issues for development and security teams.

5Veracode Package Firewall
CategorySoftware Supply Chain Security
Description

Software supply chain firewall that detects malicious open-source packages in real time and blocks downloads of compromised code from supported repositories.

6Veracode Risk Manager (ASPM)
CategoryApplication Security Posture Management
Description

Application Security Posture Management platform that correlates and contextualizes application security risks across tools and traces them back to root cause for enterprise security teams.

7Veracode Fix
CategoryAI-Powered Code Remediation
Description

AI-powered code remediation tool that automatically generates vulnerability fixes and refactors first-party code through pull requests to prevent breaking changes, for development and security teams.

8Container Security
CategoryContainer and Cloud Security
Description

Container and Kubernetes security product that scans container images and configurations to prevent vulnerabilities from reaching production environments.

9Penetration Testing as a Service (PTaaS)
CategorySecurity Testing Services
Description

Managed penetration testing service combining human expertise with automation to deliver comprehensive security testing for enterprise customers.

10Veracode eLearning
CategoryDeveloper Security Training
Description

On-demand secure coding training product for developers to build security skills aligned with their organization's coding standards.

11Security Labs
CategoryDeveloper Security Training
Description

Hands-on, interactive security training labs that let developers practice exploiting vulnerabilities in a safe environment.

12External Attack Surface Management (EASM)
CategoryAttack Surface Management
Description

External Attack Surface Management product that automatically discovers internet-exposed assets and unmanaged applications to identify shadow IT risk.

Scale indicator7 records

Each record includes

Type, Value, Description, Source

Partnership6 partners
Strategic tierStrategicTypeChannel Partner/ Reseller/ DistributorAnnounced on2026-02-25
Description

AmiViz, a Middle East-based cybersecurity and AI value-added distributor, partnered with Veracode to distribute its AI-powered application security platform across the Middle East, East Africa, and Libya. The partnership enables Veracode to expand into new geographic markets while providing AmiViz customers with tools to embed security into AI-driven software development workflows.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-07-22
Description

Veracode joined the Wiz Integration Network (WIN) to eliminate application-to-cloud security blind spots. The partnership provides unified security visibility from code to cloud.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-01-06
Description

Veracode acquired Phylum, a malicious package analysis firm, to bolster its software supply chain security. The integration aims to improve detection and blocking of malicious code in open-source libraries.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2024-04-01
Description

Veracode acquired Longbow Security, a provider of security risk management for cloud-native environments. The acquisition (now rebranded as Veracode Risk Manager) brought Application Security Posture Management (ASPM) capabilities into Veracode's suite, transforming it from code testing to comprehensive unified risk management from code to cloud.

Strategic tierRegionalTypeChannel Partner/ Reseller/ DistributorAnnounced on2024-03-18
Description

Centrico Spa, part of Sella Group, collaborated with Veracode to help secure the application development lifecycle for Italian banking and financial customers.

Strategic tierRegionalTypeImplementation/ SI/ Consulting Partner
Description

Partnership with Accion Labs to open Veracode's Prague engineering office in March 2023, expanding Veracode's global engineering capabilities.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeEmerging player
Description

ASPM and vulnerability management platform that competes with Veracode Risk Manager by aggregating findings across multiple scanning tools into a unified risk view.

TypeDirect peer
Description

Developer-first application security platform offering SAST, SCA, container, and IaC security. Snyk directly competes with Veracode across most product lines and is explicitly named on Veracode's own competitive comparison pages.

TypeDirect peer
Description

Enterprise application security testing vendor offering SAST, SCA, DAST, and IaC scanning. One of the closest direct competitors to Veracode, also named in Veracode's competitive comparisons and consistently positioned alongside it in the Gartner AST Magic Quadrant.

TypeDirect peer
Description

Synopsys' Black Duck (SCA) and Coverity (SAST) products overlap directly with Veracode's core offerings. Synopsys is named on Veracode's competitive pages and competes in the same Gartner AST and Forrester Wave evaluations.

TypeDirect peer
Description

Microsoft-owned native application security offering embedded in GitHub Enterprise, covering SAST, SCA, and secrets scanning. Named by Veracode as a primary competitor and the leading developer-native challenger leveraging Microsoft's distribution and bundling power.

TypeDirect peer
Description

OpenText Fortify offers SAST, DAST, and runtime application security. Directly competes with Veracode in the Gartner AST Magic Quadrant and is named in Veracode's competitive comparison set.

TypeEmerging player
Description

Application Security Posture Management (ASPM) emerging player focused on risk prioritization across the SDLC. Competitor to Veracode Risk Manager (formerly Longbow) in the ASPM category.

TypeDirect peer
Description

SCA-focused application security vendor that also extends into SAST and container security. Directly competes with Veracode's SCA and supply-chain security capabilities including Package Firewall.

TypeEmerging player
Description

Runtime application security via interactive application security testing (IAST) and runtime vulnerability analysis. Adjacent to Veracode's DAST and SAST offerings with an alternative instrumentation-based approach.

TypeBroad incumbent
Description

Endpoint and cloud security leader that has expanded into application security and ASPM-adjacent capabilities via acquisition. While not a specialist in Veracode's core SAST/DAST/SCA category, it competes at the platform-security-buyer level for enterprise security budgets.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers5 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment7 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile5 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration23 records

Each record includes

Title, Type, Description, Source

AI capability12 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles11 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries3 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance11 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds7 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors14 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A4 records

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Veracode

Application Security Testingveracode.com

Veracode is a private application security company founded in 2006 that sells a cloud-based Application Risk Management Platform combining SAST, DAST, SCA, container security, ASPM, AI-powered remediation, and supply chain protection to enterprise and mid-market customers across regulated industries and government.

What Veracode does

Veracode, Inc. is a privately held application security company founded in 2006 and headquartered in Burlington, Massachusetts, that sells a cloud-based Application Risk Management Platform to enterprise and mid-market organizations. The platform unifies multiple testing modalities — Static Analysis (SAST), Dynamic Analysis (DAST), Software Composition Analysis (SCA), Container Security, and External Attack Surface Management — alongside proprietary modules: Veracode Risk Manager (an ASPM solution built from the April 2024 Longbow Security acquisition), Veracode Fix (an AI-powered code remediation tool patented in April 2025), and Veracode Package Firewall (which identifies 40–50 indicators of compromise to block malicious open-source packages across NPM, PyPI, Maven, Nexus, Artifactory, and Azure Artifacts). The platform is built on a proprietary vulnerability database accumulated over two decades of scanning, currently covering 1.5M+ applications, 135M+ flaws fixed, and 448T+ lines of code, supporting a sub-1.1% false-positive rate. The product integrates deeply into developer and security workflows via IDE plugins (Eclipse, IntelliJ, VS Code, Visual Studio), CI/CD (Jenkins, Azure DevOps), SCM (GitHub, GitLab), ticketing (Jira, Bugzilla), ITSM/GRC (ServiceNow, RSA Archer), and WAF tools (Imperva, ModSecurity), and participates in the Wiz Integration Network for cloud security correlation.

Veracode generates revenue primarily through annual subscription contracts with quote-based pricing for enterprise and mid-market customers, distributed via a sales-led motion that combines direct field sales for large enterprises, inside sales for mid-market, and the Velocity Partner Program for channel distribution (with regional distributors such as AmiViz for MEA and Centrico/Sella for Italian banking). The company serves a diverse customer base spanning financial services, government/public sector, healthcare, retail/e-commerce, energy, and developers/DevSecOps teams, with named enterprise customers including HDI Global SE, Manhattan Associates, Cox Automotive, Azalea Health, and Tecnimont Services (MAIRE). The firm holds FedRAMP and StateRAMP authorizations that unlock U.S. federal, state, and local government contracts, and operates engineering offices in Prague (opened 2023 with Accion Labs) in addition to its Burlington headquarters and London EMEA office. It is backed by TA Associates following a March 2022 growth investment, has completed three acquisitions in roughly two years (Crashtest Security, Longbow Security, Phylum), and is led by CEO Brian Roche, appointed in April 2024, alongside a refreshed executive team including a new CFO, Chief Strategy Officer, and General Counsel added during 2025.

Veracode firmographics

Firmographics
Name
Veracode
Legal name
Veracode, Inc.
Website
https://veracode.com
Company type
Private
Founded year
2006
Operating status
Operating
Headcount range
501–1,000 employees
Short description
Veracode is a private application security company founded in 2006 that sells a cloud-based Application Risk Management Platform combining SAST, DAST, SCA, container security, ASPM, AI-powered remediation, and supply chain protection to enterprise and mid-market customers across regulated industries and government.
Ownership category
akta.pro rank

Veracode industry classification

Industry
Product category
Application Security Testing
NAICS
Software Publishers (5132)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
akta.pro secondary industry
Code & Repository Security (Git Security, Code Integrity) (HDADACAG)

Keywords

  • Application security testing
  • Software composition analysis
  • Application risk management
  • Static code analysis
  • Software supply chain security

Where Veracode is headquartered

Location

Headquarters

HQ city
Burlington
HQ country
United States
HQ region
North America

Offices3 records

Markets served

Veracode business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. Application Security Platform Subscription: Veracode generates revenue primarily through subscription-based licensing of its Application Risk Management Platform. Customers pay for access to security scanning tools including SAST, DAST, SCA, and AI-powered remediation capabilities.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualEnterprise and mid-market subscription tiers with quote-based pricing

Go-to-market motion1 record

Distribution channels5 records

Marketing channels7 records

Veracode product offering

Product offering

Core offering

Veracode provides a cloud-based Application Risk Management Platform that identifies security risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform combines SAST, DAST, SCA, container security, a package firewall, ASPM (Risk Manager), and AI-powered remediation (Veracode Fix), sold primarily as annual subscriptions to enterprise and mid-market organizations.

Product overview

Veracode offers a unified Application Risk Management platform designed for the AI-coding era. The portfolio centers on the Veracode Platform providing AI-driven prioritization and integrated tools to detect, understand, and remediate application vulnerabilities across the SDLC. Core testing products include SAST (Static Analysis) for source code scanning, DAST (Dynamic Analysis) for runtime web app testing, SCA (Software Composition Analysis) for open-source vulnerabilities, and Container Security for container technologies. The platform is enhanced by Veracode Fix (AI-powered code remediation that automates vulnerability fixes through pull requests), Veracode Package Firewall (supply chain protection blocking malicious packages from NPM, PyPI, Maven, Azure Artifacts, Nexus, and Artifactory), and Veracode Risk Manager (ASPM providing unified visibility and risk correlation). Additional modules include eLearning and Security Labs for developer training, PTaaS for penetration testing services, Application Security Consulting, Pipeline Scan for CI/CD integration, and External Attack Surface Management for discovering internet-exposed assets. The platform integrates with IDEs (Eclipse, IntelliJ, Visual Studio, VS Code), CI/CD tools (Jenkins, Azure DevOps), SCM systems (GitHub, GitLab), ticketing platforms (Jira, Bugzilla), and security/WAF tools (Imperva, ModSecurity). Veracode has grown through acquisitions including Longbow Security (now Risk Manager), Phylum (malicious package detection), and Crashtest Security (DAST capability).

Differentiator

Problem solved

Functional benefit

Brands

  • Veracode Risk Manager: An Application Security Posture Management (ASPM) platform that provides unified visibility and remediation of application risk. Originally developed from the Longbow Security acquisition.
  • Veracode Fix
  • Veracode Package Firewall

Products and services

  • Veracode Platform Unified Application Risk Management platform combining SAST, DAST, SCA, container security, package firewall, AI remediation, and ASPM for enterprise application security programs.
  • SAST (Static Application Security Testing) Static Application Security Testing product that scans source and binary code to find vulnerabilities during development for enterprise development teams.
  • DAST (Dynamic Application Security Testing) Dynamic Application Security Testing product that finds and fixes runtime vulnerabilities in running web applications, including AI-assisted authentication and EASM capabilities.
  • SCA (Software Composition Analysis) Software Composition Analysis product that identifies vulnerable and malicious open-source components and license compliance issues for development and security teams.
  • Veracode Package Firewall Software supply chain firewall that detects malicious open-source packages in real time and blocks downloads of compromised code from supported repositories.
  • Veracode Risk Manager (ASPM) Application Security Posture Management platform that correlates and contextualizes application security risks across tools and traces them back to root cause for enterprise security teams.
  • Veracode Fix AI-powered code remediation tool that automatically generates vulnerability fixes and refactors first-party code through pull requests to prevent breaking changes, for development and security teams.
  • Container Security Container and Kubernetes security product that scans container images and configurations to prevent vulnerabilities from reaching production environments.
  • Penetration Testing as a Service (PTaaS) Managed penetration testing service combining human expertise with automation to deliver comprehensive security testing for enterprise customers.
  • Veracode eLearning On-demand secure coding training product for developers to build security skills aligned with their organization's coding standards.
  • Security Labs Hands-on, interactive security training labs that let developers practice exploiting vulnerabilities in a safe environment.
  • External Attack Surface Management (EASM) External Attack Surface Management product that automatically discovers internet-exposed assets and unmanaged applications to identify shadow IT risk.

Quantifiable outcome

  • 184% ROI for Veracode Application Risk Management Platform customers (Total Economic Impact Study)
  • +5 more outcomes

Companies that use Veracode

Customer profile

Named customers5 records

Segments7 records

Ideal customer profiles5 records

Veracode technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration23 records

AI capability12 records

Feature6 records

Veracode partnerships and signals

Strategic signal

Partnerships

Six partnerships are on record, tiered strategic, core and regional.

  • AmiVizstrategicChannel Partner/ Reseller/ Distributor · 25 February 2026AmiViz, a Middle East-based cybersecurity and AI value-added distributor, partnered with Veracode to distribute its AI-powered application security platform across the Middle East, East Africa, and Libya. The partnership enables Veracode to expand into new geographic markets while providing AmiViz customers with tools to embed security into AI-driven software development workflows.
  • Wiz (WIN Partnership)coreTechnology or Integration · 22 July 2025Veracode joined the Wiz Integration Network (WIN) to eliminate application-to-cloud security blind spots. The partnership provides unified security visibility from code to cloud.
  • PhylumcoreTechnology or Integration · 6 January 2025Veracode acquired Phylum, a malicious package analysis firm, to bolster its software supply chain security. The integration aims to improve detection and blocking of malicious code in open-source libraries.
  • Longbow SecuritycoreStrategic or Co-development Partner · 1 April 2024Veracode acquired Longbow Security, a provider of security risk management for cloud-native environments. The acquisition (now rebranded as Veracode Risk Manager) brought Application Security Posture Management (ASPM) capabilities into Veracode's suite, transforming it from code testing to comprehensive unified risk management from code to cloud.
  • Centrico Spa (Sella Group)regionalChannel Partner/ Reseller/ Distributor · 18 March 2024Centrico Spa, part of Sella Group, collaborated with Veracode to help secure the application development lifecycle for Italian banking and financial customers.
  • Accion LabsregionalImplementation/ SI/ Consulting PartnerPartnership with Accion Labs to open Veracode's Prague engineering office in March 2023, expanding Veracode's global engineering capabilities.

Scale indicators7 records

Recent moves7 records

Expansion highlights6 records

Veracode competitors and assessment

Company assessment

Emerging players

  • ArmorCode: ASPM and vulnerability management platform that competes with Veracode Risk Manager by aggregating findings across multiple scanning tools into a unified risk view.
  • Apiiro: Application Security Posture Management (ASPM) emerging player focused on risk prioritization across the SDLC. Competitor to Veracode Risk Manager (formerly Longbow) in the ASPM category.
  • Contrast Security: Runtime application security via interactive application security testing (IAST) and runtime vulnerability analysis. Adjacent to Veracode's DAST and SAST offerings with an alternative instrumentation-based approach.

Direct peers

  • Snyk: Developer-first application security platform offering SAST, SCA, container, and IaC security. Snyk directly competes with Veracode across most product lines and is explicitly named on Veracode's own competitive comparison pages.
  • Checkmarx: Enterprise application security testing vendor offering SAST, SCA, DAST, and IaC scanning. One of the closest direct competitors to Veracode, also named in Veracode's competitive comparisons and consistently positioned alongside it in the Gartner AST Magic Quadrant.
  • Synopsys (Black Duck / Coverity): Synopsys' Black Duck (SCA) and Coverity (SAST) products overlap directly with Veracode's core offerings. Synopsys is named on Veracode's competitive pages and competes in the same Gartner AST and Forrester Wave evaluations.
  • GitHub Advanced Security: Microsoft-owned native application security offering embedded in GitHub Enterprise, covering SAST, SCA, and secrets scanning. Named by Veracode as a primary competitor and the leading developer-native challenger leveraging Microsoft's distribution and bundling power.
  • OpenText (Fortify): OpenText Fortify offers SAST, DAST, and runtime application security. Directly competes with Veracode in the Gartner AST Magic Quadrant and is named in Veracode's competitive comparison set.
  • Mend (formerly WhiteSource): SCA-focused application security vendor that also extends into SAST and container security. Directly competes with Veracode's SCA and supply-chain security capabilities including Package Firewall.

Broad incumbents

  • CrowdStrike: Endpoint and cloud security leader that has expanded into application security and ASPM-adjacent capabilities via acquisition. While not a specialist in Veracode's core SAST/DAST/SCA category, it competes at the platform-security-buyer level for enterprise security budgets.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights6 records

Customer concentration

Veracode social profiles

Digital presence

Veracode compliance and trust

Trust signal

Compliance11 records

Veracode financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Veracode leadership team

Management profile

Number of profiles

Profiles11 records

Veracode subsidiaries and ownership

Company hierarchy

Subsidiaries3 records

Veracode funding detail

Funding detail

Funding overview

Funding rounds7 records

Investors14 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Veracode M&A and investment

M&A and investment

M&A4 records

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Veracode

What does Veracode do?

Veracode provides a cloud-based Application Risk Management Platform that identifies security risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform combines SAST, DAST, SCA, container security, a package firewall, ASPM (Risk Manager), and AI-powered remediation (Veracode Fix), sold primarily as annual subscriptions to enterprise and mid-market organizations.

Is Veracode a public or private company?

Veracode is a private company. It is classified as private equity controlled and is currently operating.

When was Veracode founded?

Veracode was founded in 2006. It employs 501 to 1,000 people.

Where is Veracode based?

Veracode is headquartered in Burlington, United States, in the North America region.

How does Veracode make money?

One revenue line is on record: application Security Platform Subscription.

Who are Veracode's main competitors?

Emerging players on record are ArmorCode, Apiiro and Contrast Security. Direct peers are Snyk, Checkmarx, Synopsys (Black Duck / Coverity), GitHub Advanced Security, OpenText (Fortify) and Mend (formerly WhiteSource). CrowdStrike is listed as a broad incumbent.

Does Veracode have an API?

Yes. Veracode provides REST APIs and XML APIs that allow programmatic interaction with the Veracode Platform. The APIs enable developers to create application profiles, package and upload applications, submit applications for scanning directly from IDEs, SCM tools, and CI/CD environments, import security findings into issue tracking systems, and generate compliance reports. The platform requires access to specific region domains depending on the account region, with communication on port 443 to REST API domains. Veracode also provides API wrappers (CLI programs) for XML API communication. Developer documentation is at docs.veracode.com/r/Veracode_APIs.

What industry is Veracode in?

Veracode's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 5132 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
FinancialContent Business PageAppSec Enterprise Spend to Approach $13 Billion Globally by 2031, as Market Leaders Revealed in New Competitor LeaderboardJuniper Research forecasts enterprise application security spend to rise over 16% to $11 billion in 2026, reaching $13 billion by 2031. The study identifies vibe coding as a threat and names Veracode, Checkmarx, and Black Duck as top vendors. It urges investment in AI-aware AppSec platforms.Security BoulevardYour Coding Assistant Is Shipping Security VulnerabilitiesSalt Code, a Model Context Protocol server, advertises itself as a way to embed security policies into AI coding assistants, citing Veracode findings that 44% of security-related AI-generated code contains flaws and over 90% of vibe-coded apps have vulnerabilities. The free version provides 40 policies across OWASP, MCP, and LLM security domains, while the enterprise version covers 140-plus policies, custom policies, OAuth authentication and a usage console.TechRadarAI coding is putting software risk on steroidsA TechRadar Pro Perspectives piece by Veracode CISO Sohail Iqbal argues that generative AI has amplified software security risk by enabling machine-speed development while governance remains human-driven. Citing Veracode's 2026 State of Software Security report, it notes 82% of organizations carry security debt, 60% critical, and third-party code accounts for 66% of dangerous vulnerabilities. The author calls for automated, pipeline-enforced governance.DevOps.comAI Can Generate Your Infrastructure. Can Your CI/CD Pipeline Trust It?An opinion piece argues that AI-generated infrastructure code is less secure than application code, citing IOActive's April 2026 study showing 57.5% vulnerability in deployment infrastructure versus 59% overall, and Veracode's finding of only about 55% secure output. It recommends tagging AI-drafted changes, running IaC and secret scanners, and routing them to closer review.Tech InsiderSAST vs DAST vs SCA: AppSec Testing Compared 2026An August 2026 Tech Insider article compares SAST, DAST and SCA application security testing, using Checkmarx, Veracode and Snyk as representative vendors. It cites the October 2025 Gartner Magic Quadrant, which named Veracode, Checkmarx, Fortify and Black Duck as Leaders, and notes Snyk's $25-per-developer Team tier versus Checkmarx's $30,000 annual minimum.CSO OnlineAI can find zero-days but still can’t reliably write secure codeRecent studies by Veracode, Software Improvement Group, and Theori reveal a critical asymmetry in AI capabilities, where large language models excel at finding zero-day vulnerabilities but consistently fail to generate secure code or effective patches. Data indicates that a significant portion of AI-generated code contains known security flaws, with patch success rates averaging only 26%, prompting experts to emphasize the necessity of specialized engineering harnesses and human oversight.TechJuiceGenAI Code Fails 44% of Security Tests Despite Perfect SyntaxVeracode's 2026 GenAI Code Security Report reveals that while AI-generated code achieves near-perfect syntax, it fails security tests nearly 44% of the time due to a lack of specific security prompts. The study tested over 100 models, finding that OpenAI’s GPT-5.5 led with a 68% security pass rate, while specialized coding models performed no better than general-purpose ones.CyberScoopMore than half of AI-generated patches are brokenResearchers at 1Password tested OpenAI's ChatGPT 5.5 and Anthropic's Claude Opus 4.8 on their ability to patch six high-impact, high-complexity security vulnerabilities, finding a success rate of less than 47% — meaning AI-generated patches are more likely to fail or introduce new bugs than fully fix the original flaw. A separate Veracode study of 100 different AI models found an average security pass rate of 56%, with 44% of tests introducing detectable OWASP Top 10 vulnerabilities. The research suggests that autonomous AI vulnerability discovery and patching is not yet reliable enough for production environments, and human review remains essential despite the rapidly expanding volume of AI-generated code.AijournThe Hidden Cost of AI-Generated Code: Why Companies Still Need Developers Who Understand the FundamentalsResearch from Veracode, Anthropic, and BairesDev shows that AI-generated code carries meaningfully higher security risks, with 45% of AI-generated samples introducing at least one OWASP Top 10 vulnerability and AI-generated pull requests carrying a 2.74x higher vulnerability rate than human-written code. A controlled study by Anthropic found that junior engineers who delegated code generation to AI scored below 40% on comprehension tests versus above 65% for those who wrote code themselves, while finishing only two minutes faster on average. The article argues that companies need developers who understand programming fundamentals to critically evaluate AI-generated code rather than treating AI tools as a replacement for core skills, as the skills gap between AI-dependent and fundamentals-strong developers has become more consequential and measurable.Business Wire BlogVeracode Launches “Veracode Marketplace”: A Curated Ecosystem of Elite Security Integrations Built for the AI-Powered Software Development EraVeracode has launched the Veracode Marketplace, a curated ecosystem enabling customers to discover, evaluate, and deploy third-party security integrations as an extension of its application security platform. DryRun Security joins as the inaugural partner, bringing AI-native contextual code analysis that identifies intent-based vulnerabilities traditional static scanners miss, with the partnership delivering unified, end-to-end security coverage from detection to verified remediation. The marketplace is available today to all Veracode customers, with additional partners scheduled to join throughout 2026.