Veracode is a privately held application security vendor headquartered in Burlington, Massachusetts, founded in 2006 by security consultants with deep experience working alongside white-hat hackers. The company was created to address a persistent mismatch between fast-moving software delivery and the reality that many applications were never designed with security in mind—an issue amplified by agile development, DevOps speed pressures, increasingly complex IT environments, and a shortage of qualified security experts. Veracode’s founding vision was a cloud-native, integrated security testing platform that makes vulnerability identification and proactive remediation easy and cost-effective, especially for modern applications assembled from multiple teams, languages, frameworks, and third-party libraries.
A key differentiator is Veracode’s static binary code analysis, which assesses entire built applications rather than isolated source modules, improving visibility into cross-module and cross-language exploit paths. Over time, the platform expanded into a unified SaaS offering spanning the software development lifecycle, with strong CI/CD integrations, automation, consolidated reporting, and developer-friendly workflows. The company’s ownership changed hands multiple times—acquired by CA Technologies in 2017, then Broadcom in 2018, and later acquired from Broadcom by Thoma Bravo in late 2018—yet these transitions reportedly helped it sharpen focus on DevSecOps and platform consolidation.
Today the Veracode Application Security Platform includes Static Analysis (SAST across 24 languages, extensive frameworks and integrations, binary scanning without source access, low false positives), Dynamic Analysis (runtime web testing, scalable next-gen unified solution, recurrent scheduling, low false positives), and Software Composition Analysis (inventorying open-source/third-party components, licensing and vulnerability insights, build-blocking policies via a centralized database). Additional offerings include Veracode Verified (process-oriented certification) and Greenlight (in-IDE continuous feedback and education), plus consulting, training, and manual penetration testing with policy-aligned reporting.
See All Locations
See All Locations