Skip to main content

About Veracode email notifications

Veracode sends email notifications about your scans and other important information for specific events.

To configure notifications, see How Veracode sends notifications.

Veracode also sends optional email notifications that you can turn off.

User accounts​

EventDescription
New User ProvisionedVeracode sends email when your account is provisioned.
Password ChangedVeracode sends email any time you change your password. New users are required to change their password when they log in for the first time.
Forgot PasswordWhen you select Forgot password, Veracode sends email to help you reset your password.
Email Address ChangedVeracode sends email when you change your email address associated with your account.
API Credentials ExpiringVeracode sends email one week before your Veracode API credentials expire and another email one day before they expire. The emails explain how to generate new credentials.
User Account LockedVeracode sends an email to alert you that you are temporarily locked out of your account because of too many incorrect password attempts.

Static Analysis Upload and Scan​

EventDescription
Static Scan SubmittedVeracode sends an email to inform users that the static scan is submitted successfully, and reminding them that you still have to submit the full scan after the prescan is successful.
Static Scan CompleteVeracode sends an email stating that the results from the scan are available. The email is sent to the users in the team assigned to an application who have one or more of the following roles: Executive, Reviewer, Security Lead, Archer Reports, Results API.
Scan Results DelayedVeracode sends an email to the team assigned to the application if Veracode encounters a technical issue with the scan.
Partial Scan Results AvailableVeracode sends an email to the submitter of the scan stating that partial results for the scan are available, and they can begin viewing a portion of their results.

Dynamic Analysis​

To receive notifications for Veracode DAST, configure webhooks.

EventDescription
Prescan SuccessfulVeracode sends an email to the creator of the Dynamic Analysis scans or the last person who modified the schedule stating that the prescan passed verification.
Prescan FailedVeracode sends an email to the creator of the Dynamic Analysis scans or the last person who modified the schedule stating that the target URL configurations in the Dynamic Analysis request failed during prescan verification.
Dynamic Analysis FailedVeracode sends an email to the creator of the Dynamic Analysis scans or the last person who modified the schedule stating that the Dynamic Analysis has failed.
Results PublishedVeracode sends an email to the creator of the dynamic analysis scans or the last person who modified the schedule stating that the results of the Dynamic Analysis are published and now available.

Security policies​

EventDescription
Application Policy Is ChangedWhen the policy for an application changes, either a new policy assignment or an update to an existing policy assignment, Veracode sends an email to the team assigned to the application, to any users with the Security Lead role, and to the Business Owner email address specified in the application profile.
Grace Period ExpiresWhen the grace period is about to expire and there are flaws to be fixed, Veracode sends an email to the team assigned to the application and to any users with the Security Lead role.
New Scan for Policy DueTo remind users to perform the specified scans by a certain date according to the policy requirements from your organization, Veracode sends an email to the team assigned to the application and to any users with the Security Lead role.

Reports​

EventDescription
Shared Report AvailableVeracode sends an email to all accounts associated with the application to notify them that the results are available.

Third-Party Application Security Testing​

EventDescription
Enterprise Requests Scan of Vendor ApplicationVeracode sends an email to all users associated with the enterprise organization account, and the primary vendor contact stating that the enterprise requested a scan of their application.
Vendor Accepts Enterprise RequestVeracode sends an email stating that the vendor has accepted the request to scan their application.
Vendor Submits Scan in Response to Enterprise RequestVeracode sends an email stating that the vendor has submitted the scan for analysis.
Vendor Has Access to ResultsVeracode sends an email to the vendor owner of the application stating that scan results are available.
Scan Results Vendor Application Available to EnterpriseVeracode sends an email to the vendor owner of the application stating that scan results are available for review before publishing them to the enterprise user.
Enterprise Completes Mitigation Review for VendorVeracode sends an email stating the enterprise has completed its review of the mitigations and no additional mitigations are required.
Enterprise Requests Additional Mitigations from VendorVeracode sends an email stating the enterprise has completed its review of the mitigations and additional mitigations are required.
Enterprise Requests Remediation Plan from VendorVeracode sends an email stating the enterprise has completed its review of the mitigations and would like to discuss a remediation plan in preparation for a rescan.

eLearning​

EventDescription
Curriculum assigned to studentVeracode sends an email saying, "Thank you for using Veracode. You are assigned the completion of Curriculum_Name," to eLearning students informing them when they have assigned curriculum to complete.
Curriculum assigned to manager's teamVeracode sends an email saying, "Users who you manage have recently been assigned the following curriculum: Curriculum_Name," to eLearning managers confirming that they have assigned specific curriculum to students on their team.