Veracode
SaaS-delivered application security platform offering static, dynamic, and software composition analysis with an annual industry benchmark report.
Visit Website ↗Overview
Veracode runs application security testing as a centralized SaaS service, scanning binaries and source across static (SAST), dynamic (DAST), and software composition (SCA) analysis from a single cloud platform. It has published an annual State of Software Security research report for over a decade.
Founded in 2006 and headquartered in Burlington, Massachusetts, Veracode has changed hands several times: sold by Broadcom to Thoma Bravo in 2020, then acquired by TA Associates in 2022 at a reported $2.5 billion valuation. In January 2025 it acquired Phylum for malicious-package detection, and separately acquired Longbow Security to extend into cloud-native, code-to-cloud risk correlation.
Veracode was named a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing for the 11th consecutive time.
Innovation Matrix Assessment
Two bolt-on acquisitions (Phylum, Longbow) in the last two years, but the core scanning engine evolves incrementally.
Centralized SaaS model and long-running benchmarking give AppSec teams comparative context, though less embedded in developer tooling than newer entrants.
Stable PE-owned incumbent with an 11-year unbroken Gartner Leader streak, but no evidence of explosive growth or funding events seen at VC-backed competitors.
A well-run, mature scanning platform rather than a structurally different model; acquisitions extend rather than reinvent the core offering.
11 consecutive years as a Gartner AST Leader and a long enterprise customer base support real-world efficacy.
Active research on AI-generated code risk and the Phylum acquisition show reasonable alignment with emerging supply-chain and AI-code threats.
Why CISOs Should Care
Centralized, SaaS-delivered scanning and a decade of published flaw-density benchmarks give security leaders comparative data to justify remediation SLAs and budget.
What Makes It Different
Runs AppSec testing as a managed cloud service with a heavy research/benchmarking arm, rather than a self-serve developer tool.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
Incremental Innovator (~63/100). A durable, well-regarded incumbent with a strong analyst track record, but growth signals and category disruption are modest compared to developer-first challengers.
Editorial Note: Claims vs. Verified Findings
Gartner Leader status and the Phylum/Longbow acquisitions are independently reported. Specific customer counts and remediation-speed statistics are drawn from Veracode's own research report.
Sources
Alternatives to Veracode
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…