Veracode
Primary category: software-supply-chain.
One-liner — The other AppSec incumbent: a SaaS-first application-security platform (SAST, DAST, SCA, container, IaC) with a two-decade compliance-scanning heritage, now bolting on malicious-package detection and risk correlation.
What it does — Veracode runs the full battery of application security tests as a service: static analysis, dynamic analysis against running apps, software composition analysis on open-source dependencies, container and IaC scanning, plus manual penetration testing as a paid add-on. Its historical differentiator was binary static analysis — scanning compiled artifacts rather than requiring source — which made it the tool of choice for assessing third-party and vendor-supplied software. Recent direction is set by three tuck-ins: Crashtest Security (DAST), Longbow Security (2024 — cloud/app risk discovery and correlation, i.e. ASPM), and Phylum (Jan 2025 — detection of deliberately malicious packages in open-source registries, not just vulnerable ones).
Naming / provenance — Founded 2006 in Burlington, MA. Owned by CA Technologies (2017) via the Veracode/CA deal, passed to Broadcom with the CA acquisition, sold to Thoma Bravo in 2018, then majority-sold to TA Associates in 2022. Brian Roche succeeded Sam King as CEO in April 2024.
Ownership & viability — pe-owned, TA Associates majority since May 2022 at a reported ~$2.5B valuation. Three PE owners in eight years is a lot of turnover; each transition has come with a strategy reset. Financially stable and shipping, but this is a mature-market asset being managed for cash and multiple expansion, not a growth story. Expect incremental product work and continued tuck-ins rather than reinvention.
Positioning & differentiators —
- Binary/compiled-artifact scanning. Still the cleanest way to assess software you did not write and cannot get source for — genuinely useful in third-party due diligence, and something snyk and semgrep do not do.
- Compliance-report shape. Veracode’s output has long been formatted for the “prove to a counterparty that this app was tested” use case (its Verified programme). That is an audit artifact, not a developer workflow.
- Phylum for malicious packages. Puts it in direct competition with socket on the deliberately hostile dependency problem, which is a different threat from the known-CVE dependency problem snyk and black-duck solve.
- Weaker developer experience. The consistent criticism versus snyk, semgrep and aikido-security.
Who should choose them / anti-fit — Fits a firm that needs third-party software assessed without source access, or one whose counterparties/regulators want a named independent AppSec attestation. Anti-fit: a developer-led team optimising for inline feedback and low friction — Veracode’s centre of gravity is the security team’s report, not the pull request.
Known weaknesses / gotchas — Developer experience and scan latency are the standing complaints. Serial PE ownership means roadmap discontinuity. SaaS-only, with limited self-hosted options — a constraint for firms that will not send code or binaries out.
Deployment & data handling — SaaS. Code or compiled binaries are uploaded to Veracode for analysis, so artifacts do leave the tenancy by design. Exact retention, isolation, and training-use terms are unverified and should be diligenced before any proprietary trading code is submitted.
Integrations & partnerships — CI/CD and IDE plugins, SCM, ticketing. Detailed list and MCP/agent support unverified.
Compliance & FS traction — Long financial-services history claimed; not independently verified here. Certifications held unverified.
Commercial — Not public. Enterprise subscription, historically priced per application scanned — a model that penalises microservice estates.
Open questions
- Retention, isolation, and training-use terms for uploaded source/binaries.
- Certifications actually held (SOC 2, ISO 27001, FedRAMP).
- Named FS customers; whether per-application pricing is still the default.
- Whether Phylum’s malicious-package feed is competitive with socket’s in coverage and latency.
- TA Associates hold period — exit timing.
Sources
- TA Associates acquires majority stake in Veracode (FinTech Global) — fetched 2026-08-26 — supports: ownership, valuation; confidence: medium
- Veracode acquires Phylum technology (Veracode blog) — fetched 2026-08-26 — supports: Phylum acquisition and rationale; confidence: high (primary, vendor)
- Veracode Promotes Brian Roche to CEO, Buys Longbow Security (BankInfoSecurity) — fetched 2026-08-26 — supports: CEO change, Longbow; confidence: high
- Cached:
raw/sources/2026-08-26--veracode--ownership-and-acquisitions.md
History
- [2026-08-26] Page created via wiki-create + researched same day. Sourced from the 2026-08-25 competitor scan (Tier A, score 9).