Skip to main content

Veracode Scan Workflows

Veracode supports scan processes for these two types of workflows:

Internally developed scan workflow

In this scenario, you own the intellectual property for the application that you want to scan and have access to the source code to remediate any detected flaws. You receive a detailed list of flaws in the application with remediation guidelines.

To request a scan of your internally developed application, you must perform the procedures described in these topics in this sequence:

  1. Create an application profile
  2. Specify which teams can access an application
  3. Choose a scan type
  4. Upload a packaged application
  5. Check the scan status
  6. Review the estimated completion time for a static scan

Third-party scan workflow

In this scenario, you are purchasing or have purchased the application from a third-party vendor who controls the intellectual property for the application. The vendor has access to the source code to remediate any flaws found. You receive a summary report with a security rating and a summary of the top flaw categories found in the application, and the vendor receives a detailed list of the detected flaws with remediation guidelines.

To request a scan of an application developed by a third party, you must perform these procedures in this sequence:

  1. Request a third-party scan
  2. Choose a scan type
  3. Check the scan status

If you are a vendor receiving a third-party scan request, you must perform these procedures in this sequence:

  1. Review and accept a third-party scan request
  2. Upload a packaged application
  3. Vendor rescanning and publishing