Skip to content

Veracode

SaaS-delivered application security platform offering static, dynamic, and software composition analysis with an annual industry benchmark report.

Visit Website ↗
63/100Incremental Innovator

Overview

Veracode runs application security testing as a centralized SaaS service, scanning binaries and source across static (SAST), dynamic (DAST), and software composition (SCA) analysis from a single cloud platform. It has published an annual State of Software Security research report for over a decade.

Founded in 2006 and headquartered in Burlington, Massachusetts, Veracode has changed hands several times: sold by Broadcom to Thoma Bravo in 2020, then acquired by TA Associates in 2022 at a reported $2.5 billion valuation. In January 2025 it acquired Phylum for malicious-package detection, and separately acquired Longbow Security to extend into cloud-native, code-to-cloud risk correlation.

Veracode was named a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing for the 11th consecutive time.

Innovation Matrix Assessment

Innovation Velocity 6/10

Two bolt-on acquisitions (Phylum, Longbow) in the last two years, but the core scanning engine evolves incrementally.

Operational Value 7/10

Centralized SaaS model and long-running benchmarking give AppSec teams comparative context, though less embedded in developer tooling than newer entrants.

Market Momentum 6/10

Stable PE-owned incumbent with an 11-year unbroken Gartner Leader streak, but no evidence of explosive growth or funding events seen at VC-backed competitors.

Category Disruption 5/10

A well-run, mature scanning platform rather than a structurally different model; acquisitions extend rather than reinvent the core offering.

Real-World Efficacy 7/10

11 consecutive years as a Gartner AST Leader and a long enterprise customer base support real-world efficacy.

Enduring Relevance 7/10

Active research on AI-generated code risk and the Phylum acquisition show reasonable alignment with emerging supply-chain and AI-code threats.

Why CISOs Should Care

Centralized, SaaS-delivered scanning and a decade of published flaw-density benchmarks give security leaders comparative data to justify remediation SLAs and budget.

What Makes It Different

Runs AppSec testing as a managed cloud service with a heavy research/benchmarking arm, rather than a self-serve developer tool.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

Incremental Innovator (~63/100). A durable, well-regarded incumbent with a strong analyst track record, but growth signals and category disruption are modest compared to developer-first challengers.

Editorial Note: Claims vs. Verified Findings

Gartner Leader status and the Phylum/Longbow acquisitions are independently reported. Specific customer counts and remediation-speed statistics are drawn from Veracode's own research report.

Sources