Founded Year

2006

Stage

Acq - Fin - II | Alive

Total Raised

$114.3M

Valuation

$0000 

Revenue

$0000 

Mosaic Score
The Mosaic Score is an algorithm that measures the overall financial health and market potential of private companies.

+7 points in the past 30 days

About Veracode

Veracode provides application security solutions across sectors, including government, financial services, software, technology, retail, and healthcare. The company offers services for the software development life cycle, including vulnerability detection, static and dynamic application security testing, software composition analysis, container security, application security posture management, and penetration testing. Veracode's platform integrates into development processes, providing feedback and remediation supported by artificial intelligence to improve developer efficiency and security. It was founded in 2006 and is based in Burlington, Massachusetts.

Headquarters Location

65 Network Drive 3rd & 4th Floors

Burlington, Massachusetts, 01803,

United States

877-837-2203

Loading...

ESPs containing Veracode

The ESP matrix leverages data and analyst insight to identify and rank leading companies in a given technology landscape.

EXECUTION STRENGTH ➡MARKET STRENGTH ➡LEADERHIGHFLIEROUTPERFORMERCHALLENGER
Enterprise Tech / Development

The code review market is a space where technology vendors offer tools and solutions to help improve the quality, consistency, and speed of software development. Code review involves the systematic examination and analysis of code by developers or peers to identify errors, bugs, vulnerabilities, and adherence to coding standards. Code review tools facilitate the process by automating code analysis…

Veracode named as Leader among 12 other companies, including Sonar, Atlassian, and Qodo.

Loading...

Research containing Veracode

Get data-driven expert analysis from the CB Insights Intelligence Unit.

CB Insights Intelligence Analysts have mentioned Veracode in 1 CB Insights research brief, most recently on Feb 20, 2024.

Expert Collections containing Veracode

Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces.

Veracode is included in 3 Expert Collections, including Regtech.

R

Regtech

1,453 items

Technology that addresses regulatory challenges and facilitates the delivery of compliance requirements. Regulatory technology helps companies and regulators address challenges ranging from compliance (e.g. AML/KYC) automation and improved risk management.

C

Cybersecurity

11,228 items

These companies protect organizations from digital threats.

A

Advanced Manufacturing

6,887 items

Companies in the advanced manufacturing tech space, including companies focusing on technologies across R&D, mass production, or sustainability

Veracode Patents

Veracode has filed 54 patents.

The 3 most popular patent topics include:

  • software design patterns
  • software testing
  • machine learning
patents chart

Application Date

Grant Date

Title

Related Topics

Status

9/11/2023

2/18/2025

Software design patterns, Source code, Machine learning, Software design, Artificial intelligence

Grant

Application Date

9/11/2023

Grant Date

2/18/2025

Title

Related Topics

Software design patterns, Source code, Machine learning, Software design, Artificial intelligence

Status

Grant

Latest Veracode News

Coding With AI Assistants: Faster Performance, Bigger Flaws

Sep 5, 2025

Artificial intelligence coding assistants may easily seem like a djinn ready to make code appear out of thin air. Google and Microsoft report that a third of their new code is now AI-generated, and multiple companies are on record as strongly encouraging or mandating that their developers use AI tools. Many developers tap coding assistants as GitHub Copilot, a large language model trained on GitHub code repositories, or Cursor AI, an AI-assisted, integrated a code development environment built on Visual Studio. Another growing area involves AI command-line interactions tools such as Anthropic's Claude Code and OpenAI's Codex CLI. These "tend to be agentic - meaning they can execute commands, edit multiple files, use version control - essentially acting like a junior dev who knows how to use the terminal," said London-based software developer expert Roberto Infante, author of "AI Agents and Applications," in a May blog post. The business driver for using such tools is easy to articulate: speed. Earlier this year, many organizations were reporting a 50% increase in developer productivity thanks to such tools. A new study by Apiiro suggests recent gains are even bigger, finding that AI code assistants help developers ship code four times as quickly. That's based on its review of code bases being used by several thousand developers, comprising tens of thousands of code repositories, at some of the largest publicly traded companies in the world. But this speed comes at a cost. More code means more vulnerabilities that need to be eradicated, preferably before the code leaves the testing environment and goes into production. The reason for the increase in vulnerabilities is that code assistant LLMs are trained to emulate what real-world developers do. As a result, they produce code containing roughly the same quantity of vulnerabilities as classically built code, said said Chris Wysopal, co-founder and chief security evangelist at Veracode, in an interview at RSAC Conference 2025 in May. Noting the irony, he said that "for me, the only solution is to use more AI" by training another tool to spot bad code, thus essentially using one AI-enabled tool to fix another (see: Unpacking the Effect of AI on Secure Code Development New research suggests that besides creating an equal number of vulnerabilities as developers, AI code assistants can also introduce bigger problems. Larger Pull Requests One challenge comes in the form of how AI coding assistants tend to package their code. Rather than delivering bite-size pieces, they generally deliver larger code pull requests for porting into the main project repository. Apiiro saw AI code assistants deliver three to four times as many code commits - meaning, changes to a code repository - than non-AI code assistants, but packaging fewer pull requests. The problem is that larger PRs are inherently riskier and more time-consuming to verify. "Bigger, multi-touch PRs slow review, dilute reviewer attention and raise the odds that a subtle break slips through," said Itay Nussbaum, a product manager at Apiiro. "In one case, a single AI-driven PR changed an authorization header across multiple services. One downstream service wasn't updated. Result: a silent auth failure that could expose internal endpoints." Small Flaws Down, Big Problems Up One upside from using AI code assistants, beyond productivity, is that they appear well-versed in eliminating easy-to-spot flaws. "Our analysis shows trivial syntax errors in AI-written code dropped by 76%, and logic bugs fell by more than 60%," compared to non-AI code development, Nussbaum said. At the same time, the tools generated deeper problems, in the form of a 150% increase in architectural flaws and an 300% increase in privilege issues. "These are the kinds of issues scanners miss and reviewers struggle to spot - broken auth flows, insecure designs, systemic weaknesses," Nussbaum said. "In other words, AI is fixing the typos but creating the timebombs." The tools also have a greater tendency to leak cloud credentials. "Our analysis found that AI-assisted developers exposed Azure service principals and storage access keys nearly twice as often as their non-AI peers," Nussbaum said. "Unlike a bug that can be caught in testing, a leaked key is live access: an immediate path into production cloud infrastructure." Like Wysopal, Nussbaum said the mandate for organizations that use AI coding assistants should be clear: "If you're mandating AI coding, you must mandate AI AppSec in parallel. Otherwise, you're scaling risk at the same pace you're scaling productivity." in other words, be careful what you wish for. Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing bankinfosecurity.com, you agree to our use of cookies.

Veracode Frequently Asked Questions (FAQ)

  • When was Veracode founded?

    Veracode was founded in 2006.

  • Where is Veracode's headquarters?

    Veracode's headquarters is located at 65 Network Drive, Burlington.

  • What is Veracode's latest funding round?

    Veracode's latest funding round is Acq - Fin - II.

  • How much did Veracode raise?

    Veracode raised a total of $114.3M.

  • Who are the investors of Veracode?

    Investors of Veracode include TA Associates, Thoma Bravo, CA Technologies, Founders Circle Capital, Accomplice and 13 more.

  • Who are Veracode's competitors?

    Competitors of Veracode include CodeSecure, StackHawk, Bright Security, Chainguard, Moderne and 7 more.

Loading...

Compare Veracode to Competitors

Checkmarx Logo
Checkmarx

Checkmarx provides a platform for securing application development from code to cloud across various sectors. The company's offerings include static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and tools for API security, container security, infrastructure as code security, and malicious package protection. Checkmarx serves a range of industries, with an aim to integrate security within the software development lifecycle. It was founded in 2006 and is based in Paramus, New Jersey.

Snyk Logo
Snyk

Snyk operates in the technology sector and provides a platform for code security, open source vulnerability management, container environment protection, and infrastructure as code misconfiguration resolution. Its services offered by Snyk include continuous monitoring and actionable fix advice. It was founded in 2015 and is based in Boston, Massachusetts.

Sonar Logo
Sonar

Sonar provides tools for static code analysis, code quality assurance, and security measures for the software development industry. The company's tools integrate into CI/CD workflows and support a wide range of programming languages and frameworks. It was founded in 2008 and is based in Vernier, Switzerland.

Acunetix Logo
Acunetix

Acunetix focuses on web application and API security in the cybersecurity field. The company provides tools for discovering, testing, and patching vulnerabilities, employing automated penetration testing methods. Acunetix serves sectors including IT & Telecom, Government, Financial Services, Education, and Healthcare. It is based in United Kingdom.

Bright Security Logo
Bright Security

Bright Security specializes in dynamic application security testing (DAST) and API security within the cybersecurity industry. The company offers solutions that integrate with continuous integration and delivery (CI/CD) pipelines to identify and manage vulnerabilities in web applications and APIs, catering to the needs of developers and security teams. Bright Security's services are designed to validate business logic, provide extensive vulnerability coverage, and offer clear remediation guidelines with a focus on low false positives. It was founded in 2018 and is based in San Rafael, California.

Contrast Security Logo
Contrast Security

Contrast Security focuses on runtime application security within the cybersecurity domain. The company provides products that integrate code analysis and attack prevention into software, aimed at enhancing security observability and protection for applications. Contrast Security works with developers, application security (AppSec) teams, and security operations (SecOps) teams in various industries. It was founded in 2014 and is based in Pleasanton, California.

Loading...

CBI websites generally use certain cookies to enable better interactions with our sites and services. Use of these cookies, which may be stored on your device, permits us to improve and customize your experience. You can read more about your cookie choices at our privacy policy here. By continuing to use this site you are consenting to these choices.