Veracode provides several products that you can use to identify security issues in your application code, assess the overall security of your applications, and learn about security testing.
Select a product or product feature that meets the needs of your application security testing requirements:
- Veracode Platform
- The Veracode Platform is our core product for centrally managing your entire
application security program, including administration, security testing, and scan
results.
- Veracode Static Analysis for scanning your code and reviewing scan results.
- Veracode Software Composition Analysis (SCA) for building an inventory of your third-party components, including open-source and commercial code, to identify vulnerabilities.
- Veracode Dynamic Analysis for scanning live web applications and API specifications.
- Veracode Discovery for analyzing your web application perimeter and performing focused searches for web applications.
- Veracode Analytics for monitoring the security status of your applications and how your organization is using the Veracode Platform.
- Veracode Manual Penetration Testing for working with one or more Veracode penetration testers to perform tests and simulate real-life attacks on your web applications.
- Veracode Integrations
- Veracode provides several integrations for adding security testing to your software
development tools, such as IDEs, build systems, and ticketing systems. You can also
perform and automate most application security tasks using the Veracode APIs.
- Veracode APIs for automating your application security program, including administration, code scanning, and scan results.
- Veracode SCA Agent-Based Scanning for integrating Veracode Software Composition Analysis into your continuous integration (CI) and desktop tools.
- IDE Integrations:
- Veracode Static Analysis for uploading your code to Veracode for scanning and reviewing results from within your IDE.
- Veracode Greenlight for scanning your code and reviewing results directly in your IDE.
- Build and Release Management Systems Integrations for uploading your code to Veracode for scanning and reviewing results from within your build pipeline. You can use a Pipeline Scan to add security testing directly into your development pipeline.
- Ticketing Systems Integrations for importing and managing security findings as issues in Agile and defect-tracking tools.
- Archer Integration for assessing the Governance, Risk, and Compliance (GRC) of your applications.
- Developer Training
- Veracode provides training to help developers get started with application security testing, learn about Veracode products, and resolve security findings in their code.