AppSecNews
SAST Commercial Established

Veracode

by Veracode

Hosted application security platform whose static engine analyzes compiled binaries and bytecode rather than source, under a central policy model.

Visit veracode.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Veracode in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Language and framework support matrix changes regularly, confirm current coverage
  • Product naming across static, pipeline, SCA, DAST and manual testing offerings, confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Veracode's static engine is unusual in that it analyzes compiled output, not source. You package a build, JAR and WAR files, .NET assemblies, or binaries with debug symbols, and upload it. The engine lifts that artifact into an intermediate representation, reconstructs the control flow and call graph across the whole application including framework and library code it can see, then runs taint analysis from entry points to sinks over that model. The argument is completeness: you analyze what will actually deploy, including paths a compiler or framework introduces that never appear in a source file.

Around the engine sits a policy layer, which is the real product for most buyers. A policy defines which severities and CWE categories are unacceptable, what scan frequency is required, and how long a team has to remediate. An application passes or fails against that policy, and the result can be issued as a report to a customer, a regulator or a procurement team. The platform also offers a faster pipeline scan for pull requests, software composition analysis, dynamic scanning and human penetration testing.

Where it fits

Two speeds. A full policy scan runs against a packaged build, typically per release or on a schedule, owned by a security or compliance team. A pipeline scan runs on pull requests with a shorter turnaround and narrower scope, consumed by developers. The prerequisite is a reproducible build with debug information intact, the single largest source of onboarding friction. Build artifacts leave your environment, so this needs data handling review before a pilot.

Strengths

  • Binary and bytecode analysis covers deployed reality, including third party and generated code you do not have source for.
  • A policy model with formal pass or fail results, built for attestation, and reports that are widely accepted in customer and vendor assessments.
  • One platform spanning static, composition, dynamic and manual testing with a consolidated findings view.

Limitations

  • Packaging is the recurring operational cost. Meeting the artifact requirements for each application is real work, and failed or incomplete scans caused by packaging problems are a common complaint.
  • The upload and analyze model introduces latency that does not suit per commit feedback. The pipeline scan mitigates this but is a different, shallower analysis.
  • Hosted only for the static engine, so organizations that cannot send build artifacts outside their boundary are excluded.

Who it suits

A fit for larger organizations with compliance obligations and external attestation needs, particularly where a third party report has commercial value. A fast moving product team wanting immediate pull request feedback and minimal build coupling will find the model heavier than it wants.

Used Veracode? Recommend it under your own name and title.

Recommend this tool