All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Veracode sells application security testing whose product pages display a Forrester Wave Leader placement for static analysis, backed by twenty years of scanning and a Fortune 500 base across regulated industries. What a customer buys is a cloud platform it configures and a proprietary vulnerability database a funded rival could approach over time, so the scanning itself is the part a rival could rebuild. What slows a switch is the integration depth across a customer's pipeline, the regulated procurement review, and a FedRAMP Moderate certification a rival must also earn through the program's authorization path. Veracode fits the regulated and federal buyer, where the authorization and review slow a switch, and competes on product features alone where they do not.
| Description | Veracode runs an application risk management platform that tests software for security flaws across the development life cycle with static, dynamic, and software composition analysis plus AI-assisted fixes. | [f1] |
|---|---|---|
| Founded | 2006 | [f2] |
| HQ | Burlington, Massachusetts, USA | [f3] |
| Latest funding | TA Associates majority growth investment, March 2022, $2.5B valuation (Thoma Bravo minority) | [f3] |
| Product | What it does |
|---|---|
| Veracode Static Analysis (SAST) | Static application security testing that scans source and binary code for flaws, integrating into developer tooling with remediation guidance. |
| Veracode Dynamic Analysis (DAST) | Dynamic application security testing that scans running web applications and APIs for runtime vulnerabilities. |
| Veracode Software Composition Analysis (SCA) | Software composition analysis that finds open-source vulnerabilities and license risk and generates a software bill of materials. |
| Veracode Risk Manager | Application security posture management that unifies risk across code and cloud, built on the 2024 Longbow Security acquisition. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Risk Manager test and prioritize flaws in conventional software, so the platform is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Veracode names the enterprise application security and development team as buyer, but the AI-coding-era pain it frames stays qualitative and vendor-asserted, and the Forrester Wave placement corroborates the category rather than quantifying the pain across independent sources, so the evidence is present but unproven at the raised bar. [s1, s3, s4] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Veracode runs static, dynamic, and software composition analysis plus a cloud risk manager under one application risk management platform, and an independent evaluator rates the static analysis a Forrester Wave Leader with nine perfect scores in Q3 2025. That outside technical validation covers the static analysis, while the AI-fix and Risk Manager layers stay largely vendor-described. [s3, s1, s5] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Enterprise adoption of AI coding assistants created the faster-flowing application risk Veracode now sells against, and the platform is positioned for the AI-coding era with AI-assisted flaw fixes. Buyer-side analyst movement is present through the current Forrester static-analysis cycle and the customer growth Veracode reported across regulated industries in 2024. [s1, s3, s4] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Co-founders Chris Wysopal and Christien Rioux came from the hacker group L0pht that testified before Congress on software vulnerabilities in 1998 and founded Veracode in 2006, and the company has held a recognized application security testing position across two decades and multiple owners. Verifiable domain pedigree plus sustained category standing clear the bar for a strong team score. [s2, s5] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | Veracode reports adding more than 300 customers in 2024 across a base spanning finance, insurance, public sector, and healthcare including numerous Fortune 500 organizations, holds a current Forrester Wave Leader placement in static analysis, and draws independent customer reviews on Gartner Peer Insights. The reported customer scale across regulated industries plus independent third-party corroboration supports an at-scale gtm reading. [s4, s3, s5, s11] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Veracode is private equity owned at a 2022 valuation of 2.5 billion dollars and shows visible output, two acquisitions and more than 300 new customers in 2024, but private margins leave efficiency unconfirmable. Matches the black-duck, checkmarx, where PE ownership caps the score. [s5, s4, s9] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Veracode fits the established application security testing category buyers and analysts place without coaching, though its application risk management rebrand is vendor language that needs some explanation against the familiar SAST and SCA slots. Gartner Peer Insights independently lists Veracode in the application security testing market, corroborating the category beyond vendor framing. [s3, s1, s11, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 | A two-decade application security position, an embedded developer-pipeline workflow whose Jenkins integration appears in the public vulnerability record, and a FedRAMP federal authorization give Veracode a procurement and integration position bundling alone would not replicate quickly. The scanning capability itself remains a commodity. [s6, s3, s1, s12] |
Veracode sells application security testing to the enterprise security and development team accountable for software the business ships, and frames the new pain as application risk arriving faster in the AI-coding era. The platform positions itself to identify risk across the software development life cycle, automate flaw fixes, and simplify governance and compliance, so the segmentation rides the established AppSec buyer rather than a separately cultivated market.
The base is broad. The company reports a customer base spanning technology, finance, insurance, public sector, and healthcare, including numerous Fortune 500 organizations, evidence the segment is regulated and developer-facing rather than self-serve. That profile draws the buyer whose legal, security, and procurement review sits between the vendor and any replacement.
The public sector is a distinct segment Veracode has invested to reach. Its government platform carries a FedRAMP Moderate certification, which opens federal agencies that require authorized vendors and which can differentiate Veracode in public-sector procurement. [s1, s4, s6]
Veracode runs a wide testing portfolio under one platform rather than a single tool. Static Analysis scans source and binary code, Dynamic Analysis scans running web applications and APIs, and Software Composition Analysis finds open-source vulnerabilities and license risk while generating a software bill of materials.
The static-analysis line carries strong outside validation. An independent evaluator named Veracode a Leader in the Forrester Wave for static application security testing in Q3 2025 with nine perfect scores, which the vendor says includes perfect scores across all remediation categories, supporting the depth claim beyond marketing.
Newer layers extend from code into cloud and supply chain. Veracode Risk Manager, built on the 2024 Longbow Security acquisition, unifies risk across code and cloud, and the 2025 Phylum acquisition added detection of malicious open-source packages. The SCA line also draws on a proprietary database that the company says includes vulnerabilities not yet listed in the National Vulnerability Database. [s3, s8, s7]
Veracode competes in a crowded code-security slot against other independent application security vendors. Black Duck and Checkmarx run comparable SAST, SCA, and DAST portfolios under their own platforms, and Snyk and Semgrep contest the same buyer with developer-first motions, so the scanning capability itself is broadly available.
Veracode's differentiated position is procurement and pedigree rather than a unique scanning technique. Its FedRAMP authorization gates the federal buyer in a way rivals would need a sponsor and an assessment to match, and its two-decade record and current Forrester placement anchor an established enterprise position.
The exposure is platform bundling. GitHub Advanced Security, owned by Microsoft, can fold scanning into the developer platform enterprises already license, which pressures the commodity scanning layer even where the federal authorization and embedded workflow hold. [s6, s3, s1]
Go-to-market leans on an established enterprise motion plus outside validation. Veracode reports adding more than 300 customers in 2024, and its base names finance, insurance, public sector, and healthcare enterprises including numerous Fortune 500 organizations, the scale proof AI-native entrants in this market lack.
Third-party analyst standing reinforces the traction. The current Forrester Wave names Veracode a Leader in static application security testing, an independent placement a buyer can check rather than a vendor claim alone. Gartner Peer Insights independently lists and rates Veracode in the application security testing market, an independent customer-review reference point beyond the vendor's own pages.
The newer lines carry less proof. The Risk Manager layer from the 2024 Longbow acquisition and the AI-assisted fix capability are not yet backed by named reference customers or independent benchmarks in the public record, so their traction rides the established scanning business. [s4, s3, s7, s11]
Veracode's founding pedigree is unusually deep for the category. Co-founders Chris Wysopal and Christien Rioux came from the hacker collective L0pht, which testified before Congress on software vulnerabilities in 1998, and founded Veracode in 2006, so the domain expertise is verifiable rather than asserted.
Current leadership reflects a private-equity-backed operating company. Brian Roche became chief executive in April 2024, replacing the long-tenured prior CEO two days after the Longbow acquisition.
Category execution is the strongest sustained signal. Veracode has held a recognized application security testing position across two decades and multiple owners, alongside a research function that maintains its proprietary vulnerability data. [s2, s7, s8]
Veracode's trust posture comes from attestations, federal authorization, scale, and analyst standing. The company holds a SOC 2 Type II attestation and a FedRAMP Moderate certification for its government platform, the latter an independent federal assessment that can differentiate it in public-sector procurement.
The customer base and analyst placement reinforce readiness. A Fortune 500 base across regulated industries and a current Forrester Wave Leader placement in static analysis give a buyer external reference points beyond vendor claims.
The open item is assurance on the newer lines. The AI-assisted fix and the cloud Risk Manager built on the 2024 Longbow acquisition are newer than the company-wide attestations, so a security review will likely ask how those layers handle proprietary code and what leaves the environment. [s6, s10, s4, s3]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Black Duck | competes with | Independent private-equity-owned application security testing vendor running SAST, SCA, and DAST under the Polaris platform, contesting the same enterprise AppSec buyer. | |
| Checkmarx | competes with | Enterprise application security testing platform with proprietary SAST, SCA, and API scanning under an ASPM layer, overlapping Veracode's core code-security market. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Snyk | competes with | Developer-first security platform spanning SAST, SCA, and supply-chain scanning, contesting the same code-security buyer with a developer-led motion. | |
| Semgrep | competes with | Code-scanning and AppSec platform with a developer-first static-analysis motion overlapping Veracode's static testing line. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Veracode.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Veracode holds customers more through pipeline integration and a regulated buyer base than through the product alone. It embeds its testing across the development pipeline with broad tool integrations and policy gates, so replacing it means re-integrating and re-tuning across the estate. The buyers are regulated enterprises drawn from finance, insurance, public sector, and healthcare, whose legal and security review slows any switch. A FedRAMP Moderate certification adds a federal barrier a rival must clear through its own authorization path. What the customer buys is still a platform it configures, and the proprietary vulnerability database is content a funded rival could rebuild over time. The durable edge is integration depth in the pipeline and the federal authorization.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Veracode sells a cloud platform the customer configures and operates, and the prioritized findings, AI-assisted fixes, and database-guided remediation are automated software output rather than a managed judgment or accountability outcome a delivered service would carry. The cited platform page also lists penetration-testing and consulting services, side offerings that do not change what the platform buyer operates. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Veracode embeds in the development pipeline with broad tool integrations, including a Jenkins plugin the public vulnerability record names, configured policy gates, and the software bill of materials the SCA line generates and monitors, so replacing it means re-integrating and re-tuning across the development estate, meaningful friction in effort rather than network effects or mandated data residency. Matches the black-duck, checkmarx. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | Veracode holds a FedRAMP Moderate certification for its government platform alongside a SOC 2 Type II attestation, and the federal authorization gates the public-sector buyer above table stakes through the program's authorization process. Above the black-duck, checkmarx, and below 3 because the authorization is held by other vendors too rather than a mandate naming Veracode. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Static source and binary analysis, dynamic web and API scanning, software composition analysis, and a maintained vulnerability database sit in program-analysis territory that takes years of specialized expertise to build, evidenced by a two-decade engineering history and a vendor-displayed Forrester Leader placement in static analysis. Matches the black-duck, checkmarx. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers are regulated enterprises with strict procurement reviews, drawn from a base spanning finance, insurance, public sector, and healthcare including numerous Fortune 500 organizations, the population whose legal and security review sits between the vendor and replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Veracode is a cloud platform with application features that scan, score, and gate code in the development pipeline rather than infrastructure customer traffic is forced through inline, so removing it costs coverage rather than breaking production traffic. Matches the black-duck, checkmarx. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Veracode's SCA line draws on a proprietary database the company says includes vulnerabilities not yet listed in the National Vulnerability Database, but the cited record includes no independent benchmark of that database, and on the analysis it reads as a curated dataset a funded rival could approach over time, the named-corpus default for an unevidenced content asset rather than an irreplaceable one. |
Veracode sells application security testing to the enterprise security and development team accountable for software the business ships, and frames the new pain as application risk arriving faster in the AI-coding era. The platform positions itself to identify risk across the software development life cycle, automate flaw fixes, and simplify governance, so the segmentation rides the established application security buyer rather than a separately cultivated market.
The base is broad. Veracode reports a customer base spanning technology, finance, insurance, public sector, and healthcare, including numerous Fortune 500 organizations, evidence the segment is regulated and developer-facing rather than self-serve. That population brings legal and security review that sits between the vendor and any replacement.
The public sector is a distinct segment Veracode invested to reach. Its government platform carries a FedRAMP Moderate certification, which opens federal agencies that require authorized vendors, a federal authorization that can differentiate Veracode in public-sector procurement.
Veracode runs a wide testing portfolio under one platform rather than a single tool. Static Analysis scans source and binary code, Dynamic Analysis scans running web applications and APIs, and Software Composition Analysis finds open-source vulnerabilities and license risk while generating a software bill of materials, with over twenty years of static-analysis engineering behind the scanning service.
The static-analysis line carries the strongest outside recognition. Veracode's product page displays a Leader placement in the Forrester Wave for static application security testing with nine perfect scores, a third-party analyst result reported on the vendor's own page in the fetched record.
Newer layers extend from code into cloud and supply chain. Veracode Risk Manager, built on the 2024 Longbow Security acquisition, unifies risk across code and cloud, and the 2025 Phylum acquisition added detection of malicious open-source packages. The SCA line draws on a proprietary database the company says includes vulnerabilities not yet listed in the National Vulnerability Database, though the fetched record did not include an independent public benchmark for the database, so its defensibility is harder to verify externally.
Go-to-market leans on an established enterprise motion plus outside recognition. Veracode reports adding more than 300 customers in 2024, and its base names finance, insurance, public sector, and healthcare enterprises including numerous Fortune 500 organizations, a scale signal the cited record supports.
Third-party analyst standing reinforces the traction. Veracode's pages display a current Forrester Wave Leader placement in static application security testing, a third-party result a buyer can verify with Forrester, and the company carries a long-standing application security testing position. Gartner Peer Insights independently lists and rates Veracode in the application security testing market, an independent customer-review reference point a buyer can check.
The newer lines carry less proof. The Risk Manager layer from the 2024 Longbow acquisition and the AI-assisted fix capability are not yet backed by named reference customers or independent benchmarks in the fetched record, so their traction rides the established scanning business rather than standing on its own.
Veracode does not publish a public rate card for its testing portfolio. The product pages route the buyer to a demo request and a sales contact rather than a self-serve price, consistent with a vendor selling negotiated enterprise agreements rather than to self-service developers.
The buying unit follows the established application security motion. The platform consolidates static, dynamic, and software composition analysis, but the fetched pages disclose no charging unit or metering basis, so how cost scales across a customer's estate is not visible in the public record.
The fetched record does not document pricing for the newer lines. Veracode Risk Manager and the AI-fix capability route the buyer to a demo without published packaging, so the cost basis for the AI-coding-era layers is not visible to a buyer comparing them against rival offerings.
Veracode delivers as a cloud-based platform, so the customer configures policy and scans rather than running testing infrastructure on premises. The static-analysis service integrates broadly into developer tooling, placing scanning where developers already work rather than as a separate console.
Operations target developer-speed feedback. The platform applies policy-driven gates and prioritizes findings, and the SCA line generates a persistent software bill of materials and monitors components for emergent risk, the continuous operation an enterprise application security program runs day to day.
Cloud-based delivery shapes the deployment question. Because Veracode is presented as a cloud-based platform, a buyer with strict code-residency requirements should validate deployment options and weigh them against rivals that scan locally.
Trust rests on attestations, federal authorization, scale, and analyst standing. Veracode publishes a SOC 2 Type II attestation covering security, availability, and confidentiality, and holds a FedRAMP Moderate certification for its government platform, an independent federal assessment that can differentiate it in public-sector procurement.
The customer base and analyst placement reinforce readiness. A Fortune 500 base across regulated industries and a vendor-displayed Forrester Wave Leader placement in static analysis give a buyer reference points to check, and the founding pedigree from the L0pht security collective lends domain credibility.
The open item is assurance on the newer lines. The AI-assisted fix and the cloud Risk Manager built on the 2024 Longbow acquisition are newer than the company-wide attestations, so a security review will likely ask how those layers handle proprietary code and what leaves the environment, which the fetched pages do not document for the new products.
Veracode is built to be the single application security platform for a development organization. The platform consolidates static, dynamic, and software composition analysis plus cloud risk management into one surface, so a buyer can replace fragmented point tools with one vendor, the consolidation Veracode sells.
Outward, the line integrates into the developer ecosystem. The static-analysis service connects broadly across developer tools and meets developers in their existing pipeline rather than binding to one vendor stack, which widens reach into the development workflow.
Inward, adoption deepens reliance on Veracode. Standardizing on the platform concentrates a customer's scanning and risk scoring with one vendor, though the SBOMs themselves export in portable CycloneDX and SPDX formats, and the proprietary vulnerability database is a Veracode-controlled input the customer cannot reproduce, which is both the value a buyer consolidates onto and the concentration a buyer wary of single-vendor dependence weighs against it.
Veracode's founding pedigree is unusually deep for the category. Co-founders Chris Wysopal and Christien Rioux came from the hacker collective L0pht, which testified before Congress on software vulnerabilities in 1998, and founded Veracode in 2006, so the domain expertise is verifiable rather than asserted.
Current leadership reflects a private-equity-backed operating company. Brian Roche became chief executive in April 2024, replacing long-tenured CEO Sam King, two days after the Longbow acquisition.
The strongest sustained team signal is category execution. Veracode has held a recognized application security testing position across two decades and multiple owners, alongside a research function that maintains its proprietary vulnerability data, evidence of an organization that has sustained an analyst-recognized position through ownership changes.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Veracode Application Risk Management Platform | official | 2026-06-21 |
| f2 | About Veracode (founded by Chris Wysopal and Christien Rioux) | official | 2026-06-21 |
| f3 | TA Associates growth investment in Veracode (Burlington dateline) | press | 2026-06-21 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Veracode Application Risk Management Platform “Identify, prioritize, and mitigate application risk across your entire SDLC with AI-powered precision.” | official | 2026-06-21 |
| s2 | About Veracode (L0pht founders Chris Wysopal and Christien Rioux) “In 1998, the hacker group L0pht testified before Congress to expose software vulnerabilities. In 2006, members Chris Wysopal and Christien Rioux founded Veracode.” | official | 2026-06-21 |
| s3 | Veracode Static Analysis (Forrester Wave SAST Leader Q3 2025) “Veracode has been recognized as a Leader in The Forrester Wave: Static Application Security Testing Solutions, Q3 2025, achieving 9 perfect scores, more than any competitor.” | official | 2026-06-21 |
| s4 | Veracode adds over 300 customers and completes acquisitions in 2024 “The company's customer base includes enterprises spanning technology, finance, insurance, public sector, and healthcare industries, including numerous Fortune 500 organizations.” | press | 2026-06-21 |
| s5 | Veracode Announces Significant Growth Investment from TA Associates ($2.5B valuation) “The transaction, which values Veracode at $2.5B, is expected to be completed in Q2 2022. An eight-time leader in the Gartner Magic Quadrant for Application Security Testing.” | press | 2026-06-21 |
| s6 | FedRAMP Marketplace: Veracode Online Security Platform for Government (Certified, Class C Moderate) “Veracode Online Security Platform for Government. FedRAMP Certified. As of 7/18/2022. Certification Class C (Moderate). Certification Type Rev5.” | regulatory | 2026-06-21 |
| s7 | Veracode Promotes Brian Roche to CEO, Buys Longbow Security “Veracode appointed Brian Roche chief executive just two days after purchasing startup Longbow Security to give companies a centralized view of risk for cloud assets and applications.” | press | 2026-06-21 |
| s8 | Veracode Software Composition Analysis “Uncover known, hidden, and emerging risks with our proprietary database, including vulnerabilities not yet listed in the National Vulnerability Database (NVD).” | official | 2026-06-21 |
| s9 | Veracode (Wikipedia): ownership history and Phylum acquisition “In March 2022, the company was acquired by TA Associates at a valuation of $2.5 billion. In January 2025, Veracode acquired Phylum Inc.” | other | 2026-06-21 |
| s10 | Veracode Security Certifications (SOC 2 Type II) “Veracode has received a SOC 2 Type II attestation report, verifying that we have implemented effective controls to protect the security, availability, and confidentiality of customer data.” | official | 2026-06-21 |
| s11 | Gartner Peer Insights: Veracode in the Application Security Testing market, 4.5/5 from 432 ratings “Veracode is a software focused on application security, offering tools for static analysis, dynamic analysis, software composition analysis, and manual penetration testing.” | other | 2026-06-29 |
| s12 | NVD: CVE-2023-25722, credential-leak in Veracode Scan Jenkins Plugin and Azure DevOps Extension (CVSS 5.5 Medium) “A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the Jenkins remote)” | other | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Veracode Application Risk Management Platform “Identify, prioritize, and mitigate application risk across your entire SDLC with AI-powered precision.” | official | 2026-06-21 |
| s2 | About Veracode (L0pht founders Chris Wysopal and Christien Rioux) “In 1998, the hacker group L0pht testified before Congress to expose software vulnerabilities. In 2006, members Chris Wysopal and Christien Rioux founded Veracode.” | official | 2026-06-21 |
| s3 | Veracode Static Analysis (Forrester Wave SAST Leader Q3 2025) “Veracode has been recognized as a Leader in The Forrester Wave: Static Application Security Testing Solutions, Q3 2025, achieving 9 perfect scores, more than any competitor.” | official | 2026-06-21 |
| s4 | Veracode adds over 300 customers and completes acquisitions in 2024 “The company's customer base includes enterprises spanning technology, finance, insurance, public sector, and healthcare industries, including numerous Fortune 500 organizations.” | press | 2026-06-21 |
| s5 | Veracode Announces Significant Growth Investment from TA Associates ($2.5B valuation) “Veracode's current majority investor, Thoma Bravo, a leading software investment firm, will retain a minority position in the business. The transaction, which values Veracode at $2.5B” | press | 2026-06-21 |
| s6 | FedRAMP Marketplace: Veracode Online Security Platform for Government (Certified, Class C Moderate) “Veracode Online Security Platform for Government. FedRAMP Certified. As of 7/18/2022. Certification Class C (Moderate). Certification Type Rev5.” | regulatory | 2026-06-21 |
| s7 | Veracode Promotes Brian Roche to CEO, Buys Longbow Security “Veracode appointed Brian Roche chief executive just two days after purchasing startup Longbow Security to give companies a centralized view of risk for cloud assets and applications.” | press | 2026-06-21 |
| s8 | Veracode Software Composition Analysis (proprietary vulnerability database) “Uncover known, hidden, and emerging risks with our proprietary database, including vulnerabilities not yet listed in the National Vulnerability Database (NVD).” | official | 2026-06-21 |
| s9 | Veracode Security Certifications (SOC 2 Type II) “Veracode has received a SOC 2 Type II attestation report, verifying that we have implemented effective controls to protect the security, availability, and confidentiality of customer data.” | official | 2026-06-21 |
| s10 | Veracode Static Analysis product page (over 20 years, developer integrations) “Pioneering SAST for over 20 years, we lead the industry by meeting developers where they work with our next-generation Adaptable SAST Scanning Service.” | official | 2026-06-21 |
| s11 | Veracode (Wikipedia): Phylum acquisition and ownership history “In April 2024, Brian Roche replaced Sam King as CEO, following Veracode's acquisition of Longbow Security. In January 2025, Veracode acquired Phylum Inc.” | other | 2026-06-21 |
| s12 | Gartner Peer Insights: Veracode in the Application Security Testing market, 4.5/5 from 432 ratings “Veracode is a software focused on application security, offering tools for static analysis, dynamic analysis, software composition analysis, and manual penetration testing.” | other | 2026-06-29 |
| s13 | NVD: CVE-2023-25722, credential-leak in Veracode Scan Jenkins Plugin and Azure DevOps Extension (CVSS 5.5 Medium) “A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the Jenkins remote)” | other | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.