Veracode / veracode.com
AI-powered application security testing platform providing SAST, SCA, DAST, binary analysis, and AI fix capability for enterprise software development and supply chain security.
Pricing
Free
Free plan
No
Category
Developer Tools
Platforms
4
Free plan
No
API access
No
Open source
No
Platforms
4
Veracode is an enterprise application security platform providing comprehensive testing across the software development lifecycle — static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), binary scanning, and manual penetration testing. Veracode Fix is the AI capability — using generative AI to automatically generate code fixes for identified security flaws. Veracode Fix provides AI-generated code patches that developers can review and apply in one click, dramatically reducing the time between security finding and remediation. Binary Analysis is Veracode's distinctive capability — scanning compiled binaries and bytecode rather than requiring access to source code. This enables security testing of third-party and legacy applications where source code is unavailable, and provides a different vulnerability perspective than source-only SAST. Veracode's cloud-based delivery model eliminates on-premise scanner deployment — security scanning is performed in the cloud, removing infrastructure management from enterprise security teams. Software Risk Manager provides unified application security posture — consolidating findings from Veracode and third-party scanners into one risk management view. Veracode's policy-based approach enables setting organisation-wide security policies that determine which findings must be fixed before release. With customers including Adobe, IBM, and Expedia, Veracode validates for enterprise software development and procurement security.
Veracode AI runs as llm assistant software built around code and text workflows. Users typically start with a prompt, upload, or connected data source, and the underlying model handles the heavy lifting before returning a result you can refine or export. It's available on web, ide plugins, and ci/cd.
The capabilities that matter most for teams evaluating Veracode AI.
AI-generated code patches for security vulnerabilities — one-click fix candidates reducing time from vulnerability identification to remediation for developer-facing security testing.
Scanning compiled binaries without source code — uniquely enabling security testing of third-party components and legacy applications that source-based SAST tools cannot scan.
Unified application security posture consolidating Veracode and third-party scanner findings — single risk view across the application security programme.
Enterprise licensing. No public pricing. Annual contracts. Privately held (Broadcom subsidiary). Demo available.
Model
Enterprise
Starting price
Free
Free trial
Yes
Checkmarx (rank 812) provides full-spectrum AST with AI remediation. Snyk (covered) provides developer-first SCA and SAST. GitHub Advanced Security provides scanning within GitHub. Semgrep provides lightweight SAST.
A side-by-side look at the closest alternative in this category.
Key facts about model providers, platforms, and team support.
Model Provider
OpenAI, Veracode
Platforms
Web, IDE plugins, CI/CD, API
Deployment
SaaS
Integrations
GitHub, GitLab, Jenkins, Jira, Azure DevOps, API
Team Collaboration
No
Launch Year
2023
Compliance signals and data-handling notes as reported by the vendor.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP authorised. Enterprise data handling agreements.
Source code and binary application data transmitted to Veracode cloud for analysis. FedRAMP for US government application security scanning.
Editorial Verdict
Veracode is a strong AI application security platform for enterprises wanting binary analysis capability, AI code fix suggestions, and policy-based release gate enforcement for software development and supply chain security.
Last verified July 24, 2026.
Enterprise licensing. No public pricing. Annual contracts. Privately held (Broadcom subsidiary). Demo available.
Enterprise licensing. No public pricing. Annual contracts. Private company (Hellman & Friedman). Demo available.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP authorised. Enterprise data handling agreements.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP eligible. Enterprise data handling agreements.
Source code and binary application data transmitted to Veracode cloud for analysis. FedRAMP for US government application security scanning.
Source code and vulnerability scan data processed on Checkmarx cloud or customer on-premise. Code scanning occurs locally in CI/CD pipelines — code transmitted to cloud for reporting and management.
Verified reviews from signed-in users, stored in the backend and averaged into this tool's rating.
Sign in to rate Veracode AI and leave a review.
No other reviews yet — be the first to share how this tool performs in practice.