Veracode Features
The most important feature that makes the world's most preferred software security testing tool unique is that it is cloud-based and always up-to-date.
Cloud-Based Scanning
Gartner Magic Quadrant Leader
API Support
Join the ranks of privileged users!
Dynamic Analysis - DAST
Static Analysis - SAST
Veracode Usage Fields
Web Applications
Scanning & Tracking
Many organizations operate with thousands of web-based applications. Within these applications, there may be unwanted marketing sites or deceptive sites derived from specific content and made to resemble the legitimate ones.
Veracode scans these internet-facing websites and provides detailed security information about newly added services and launched sites. This allows you to identify trusted site addresses for the web application firewalls (WAFs) used within your organization. Veracode provides an infrastructure capable of scanning thousands of websites simultaneously, helping protect your organization against vulnerabilities found on those sites.
Third-Party Applications
Application Security
Almost two-thirds of enterprise applications are purchased from external sources. While most of these applications are developed and sold by commercial companies, they can also be custom-developed applications, applications acquired as SaaS, or third-party libraries.
The Vendor Application Security Testing Program (VAST) ensures that all these applications and services are tested to guarantee the security of the code you use or develop. This prevents you from being affected by vulnerabilities that do not originate from you.
Mobile Environments
Application Security
Veracode can uncover risks in mobile applications by running them in real time using behavioral analysis and dynamic call analysis. Following these tests, it can model many security threats—such as suspicious geographic locations, unauthorized data sharing, and unauthorized access to data on the mobile device—and detect malware.
This is a highly preferred scan, especially for organizations that allow employees to use their own devices (BYOD) or do not restrict the programs to be installed on the mobile devices they provide.






