Full-Time
Updated on 8/19/2026
Cloud-based platform for application security scanning
No salary listed
Burlington, MA, USA
In Person
Bachelor's
See people who can refer or advise you
Placeholder
Company Size
201-500
Company Stage
Acquired
Total Funding
$114.3M
Headquarters
New York City, New York
Founded
2006
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Wellness Program
Unlimited Paid Time Off
401(k) Company Match
401(k) Retirement Plan
Professional Development Budget
Veracode named Overall Leader in 2026 KuppingerCole Software Supply Chain Security Leadership Compass. News | 18.08.2026 Software supply chain attacks are accelerating, and CISOs need proof that their vendor can not only detect risk but actively block and remediate it. Compromised build systems, malicious open-source packages, and evolving regulations such as the EU Cyber Resilience Act and US Executive Order 14028 have made software supply chain security a board-level priority. Independent analyst validation is now a critical factor when IT leaders select an application risk management platform. What was announced. Veracode announced on August 6, 2026 that it has been named the Overall Leader in the 2026 KuppingerCole Analysts Leadership Compass: Software Supply Chain Security for the second consecutive time since the report was first published. Veracode is positioned at the top of the Overall Leader, Product Leader, and Innovation Leader categories, and is also recognized as a Market Leader. The KuppingerCole Analysts Leadership Compass assesses vendors on product strength, market presence, and innovation. The report was authored by Jonathan Care, an expert in cybersecurity and fraud detection and a Fellow of the British Computer Society. Veracode earns its Overall Leadership position by evolving from application scanning into a unified application risk management platform, pairing mature application security testing with a dedicated software supply chain layer. Its Package Firewall blocks malicious open-source packages before they enter the codebase, while its first-to-market, AI-powered Fix capability gives developers remediation choices rather than just flagging problems. KuppingerCole Analysts, 2026 Leadership Compass Why this matters. For CIOs, CISOs, and procurement leaders, this recognition provides third-party validation that Veracode combines mature Application Security Testing with proactive supply chain controls. As regulatory pressure grows under the UK Cyber Security Bill, EU CRA, and NIST SSDF, organizations need consolidated ASPM visibility, automated remediation, and evidence of enterprise-grade compliance such as SOC 2 Type II. This recognition reflects what Softprom hear from customers every day: they don't just want visibility into supply chain risk, they want it stopped and fixed automatically. As supply chain attacks grow more sophisticated, security teams need a partner that closes the gap between finding a risk and fixing it. Ajay Nigam, Chief Product Officer at Veracode Technical details. * Static Analysis: Support for 130+ languages with a market-leading low false-positive rate. * Package Firewall: Blocks malicious open-source packages at the point of ingestion. * Malicious Package Detection: Analyzes new packages within seconds. * Veracode Fix: AI-powered engine that proposes and applies remediation. * Proprietary suite: Static Analysis, SCA, Dynamic Analysis, Container Security, and Veracode Risk Manager, with no OEM dependencies. * ASPM: Consolidated findings across code to cloud via Veracode Risk Manager. * Integrations: Broad CI/CD, IDE, and registry integration ecosystem. * Compliance: SOC 2 Type II certified, aligned with NIST SSDF, EU CRA, and Executive Order 14028. Softprom and Veracode. Softprom is the official distributor of Veracode. Its team helps enterprises deploy application risk management, software composition analysis, and supply chain security controls tailored to regulatory and business requirements. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.
Veracode Marketplace 2026: curated AppSec integrations for the AI era. News | 04.08.2026 Application security teams face a growing challenge: AI-generated code, agentic development environments, and expanding attack surfaces demand deeper contextual analysis than traditional static scanners can provide. Enterprises need a trusted way to extend their existing AppSec platform with specialized capabilities without adding procurement friction or fragmented workflows. A single, curated destination to discover, evaluate, and deploy elite security integrations on top of Veracode. What was announced. On July 30, 2026, Veracode announced the launch of the Veracode Marketplace, a curated ecosystem that provides customers with a single, trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. The marketplace debuts with DryRun Security as its inaugural partner, delivering AI-native contextual analysis and verification to Veracode customers on day one. Every partner is vetted for technical depth, product quality, and workflow fit. Integrations are anchored to Veracode findings for a unified audit trail, and every purchase runs through a single procurement path on a single contract with a personalized support experience. Additional partners are scheduled to join throughout 2026. Application security has entered a new era, and no single vendor will solve it alone. Customers tell Softprom they want the depth and rigor of the Veracode platform, combined with the freedom to choose specialized capabilities that fit their tech stack Ajay Nigam, Chief Product Officer at Veracode Why this matters. For CIOs, CISOs, IT directors, and procurement leaders, the Veracode Marketplace addresses three critical pressures: the need to secure AI-generated code, the demand for verified risk prioritization over noisy findings, and the operational cost of managing multiple security vendors. By consolidating validated integrations under a single contract anchored to Veracode findings, enterprises reduce procurement overhead and gain a unified audit trail across their AppSec program. The inaugural partnership with DryRun Security is significant: DryRun already powers more than 500,000 code reviews per month and provides native integrations with modern AI coding tools including Claude Code, Cursor, Codex, GitHub, and GitLab. Combining Veracode's deterministic scanning with DryRun's AI-reasoning delivers unified, end-to-end coverage from detection to validated remediation. Technical details. * Curated ecosystem: vetted third-party integrations extending the Veracode platform. * Inaugural partner: DryRun Security, with AI-native Contextual Security Analysis engine. * Coverage expansion: intent-based and logic vulnerabilities missed by traditional static scanners. * Native integrations: Claude Code, Cursor, Codex, GitHub, GitLab, plus repository-wide DeepScans. * Scale: DryRun powers over 500,000 code reviews per month. * Procurement: single contract, unified audit trail, personalized support. * Availability: live today for Veracode customers, with additional partners in 2026. Application security teams are not asking for more findings - they are asking for better verification of which risks actually matter James Wickett, CEO and Co-Founder of DryRun Security Softprom and Veracode. Softprom is the official distributor of Veracode. Enterprise teams looking to adopt the Veracode Marketplace, integrate DryRun Security, or expand their AppSec program can request a consultation and demo through Softprom's certified specialists. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.
Superblocks and AWS announce strategic collaboration. August 03, 2026 Superblocks and Amazon Web Services (AWS) announced a multi-year collaboration to make Superblocks' generative AI platform available within customers' AWS environments, including Amazon Bedrock. Amazon Bedrock is a platform for building generative AI applications and agents at production scale, providing access to a broad selection of fully managed models from leading AI companies through a unified API. As a result, enterprise customers will be able to build, secure, and deploy AI applications while leveraging the security, privacy, and performance of AWS. As part of the collaboration, Superblocks will integrate with Amazon Aurora to spin up databases for new AI-generated applications with best-in-class price-performance and scale-to-zero capabilities within the customer's environment. Amazon Aurora is a fully managed, high-performance relational database service built for the cloud, delivering up to 6x the throughput of standard engines along with automatic scaling and enterprise-grade security at global scale. Superblocks provides both the AI coding capabilities and governance layer for enterprise-grade vibe coding, enabling business teams to deliver IT-approved applications on a self-serve basis while IT and security teams centrally control auditing and security. Bringing Superblocks to Amazon Bedrock, Amazon EC2, and Amazon Aurora gives enterprises an org-wide capability to deliver internal applications built by business teams - with all data and code secured within their trusted security perimeter in AWS through Superblocks' Cloud-Prem deployment model. Superblocks' AWS Cloud-Prem model gives enterprises the speed of a managed AI application platform while allowing IT and security teams to preserve their existing AWS network controls, governance policies, and production security requirements. Superblocks Smart Router on Amazon Bedrock delivers up to 30% cost savings by intelligently matching each task to the most cost-effective model. It reserves frontier models only when they're needed, as open-source models increasingly close the performance gap. "Customers are done being beholden to expensive frontier models. They want model choice that delivers the best price-performance for every task, and that's exactly what Superblocks Smart Router offers, with the security and performance of Amazon Bedrock behind it," said Brad Menezes, CEO of Superblocks. "Today, business users are vibe coding on their local desktops with no secure path to production on top of their private enterprise data. Our partnership with AWS provides the infrastructure for that secure path, and it lets IT teams configure policy agents that check AI-generated code against enterprise standards before it ever reaches production." "Giving AWS customers the flexibility to run Superblocks in their own virtual private cloud with model choice on Amazon Bedrock means business teams can build AI applications on enterprise data without putting security at risk," said Jason Bennett, Vice President and Global Head of Startups and Venture Capital at AWS. "Enterprises want speed and control - Superblocks delivers both, enabling self-serve automation org-wide while IT maintains governance. That's what successful AI adoption at scale looks like." As part of the collaboration, AWS will serve as Superblocks' preferred cloud provider, and both companies will co-market this new offering to customers leveraging AWS field enablement, as well as promote hands-on AI app development workshops to help enterprises move from AI prototypes to governed production applications on AWS. Customers will also be able to procure Superblocks through AWS Marketplace, simplifying contracting, budget alignment, and committed-spend utilization for AWS customers adopting Superblocks across business teams. Industry news. August 03, 2026 Superblocks and Amazon Web Services (AWS) announced a multi-year collaboration to make Superblocks' generative AI platform available within customers' AWS environments, including Amazon Bedrock. August 03, 2026 BrowserStack announced Test Companion, agentic AI for test automation built into the IDE. August 03, 2026 Veracode announced the launch of the Veracode Marketplace, a curated ecosystem that gives customers a single, trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. July 30, 2026 Oracle and Google Cloud have expanded their partnership to bring Google's Gemini models to Oracle's extensive portfolio of enterprise applications. July 30, 2026 Tricentis announced the acquisition of Tabnine, the AI-coding platform purpose-built for secure, context-aware enterprise software development. July 29, 2026 Checkmarx announced Checkmarx Fusion, a new hybrid scanning approach now available in early access to Checkmarx customers. July 29, 2026 Evinced announced the launch of its suite of agentic coding tools: Autopilot, Harness, and Resolve. July 28, 2026 The Agentic AI Foundation (AAIF) announced the largest update to the Model Context Protocol (MCP) since its launch. This update removes the biggest technical roadblocks, making it easier for Fortune 500 and AI labs to use AI agents at scale. What's new: - Stateless architecture that scales on HTTP infrastructure - Enterprise-grade security that aligns with the security standards companies already use (OAuth 2.0 and OpenID Connect) - Formal governance via a predictable, 12 month deprecation policy July 28, 2026 Opsera announced the availability of Forge, an enterprise software factory, on the Cursor Marketplace. July 27, 2026 Decisions announced its latest release, Decisions Platform v10, a major update to its enterprise orchestration platform that advances how organizations build, govern, deploy, and orchestrate automation at scale. July 23, 2026 Azul announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. July 23, 2026 Prismatic announced native large data sync, a set of new capabilities that enables teams to move high volumes of customer data through the same integration platform they already use to build, deploy, monitor, and manage customer-facing integrations. July 23, 2026 Harness and Kong announced an expansion of their strategic partnership to address the growing security challenges posed by AI-driven architectures, autonomous agents, and Model Context Protocol (MCP) deployments. July 22, 2026 Sauce Labs introduced AURA, its AI-Unified Release Assurance platform, to close that gap.
Veracode has launched the Veracode Marketplace, a curated ecosystem allowing customers to discover and deploy third-party security integrations that extend its application risk management platform. The marketplace debuts with DryRun Security as its inaugural partner. DryRun Security brings AI-native code analysis to Veracode customers, offering contextual security analysis that identifies complex logic and intent-based vulnerabilities traditional static scanners miss. The company currently powers over 500,000 code reviews monthly. Every marketplace partner undergoes vetting for technical depth and product quality. Integrations connect to Veracode findings for unified audit trails, with purchases processed through a single contract. "Application security has entered a new era, and no single vendor will solve it alone," said Ajay Nigam, chief product officer at Veracode. Additional partners are scheduled to join throughout 2026. The marketplace is available to all Veracode customers through its platform.
Veracode unveils ai-powered innovations for software security 2025. News | 21.07.2026 Advanced ai-powered solutions reduce remediation time while proactively blocking 60% of critical supply chain threats. Enterprise security teams face a paradox: they are overwhelmed by vulnerability alerts yet still miss the risks that matter most. With 70 percent of critical security debt now stemming from third-party code and regulations such as the EU Digital Operational Resilience Act (DORA) tightening expectations, organizations need proactive controls across the software development lifecycle rather than reactive firefighting. What was announced. Veracode has introduced a suite of innovations to its Application Risk Management platform that reduce vulnerability remediation time by up to 92 percent and prevent 60 percent of critical supply chain risk from entering organizations. The updates cover Veracode Risk Manager, Veracode Package Firewall, and developer productivity tools. Veracode Risk Manager now includes six new integrations with industry leaders such as Wiz, aggregating and prioritizing issues across sources so security teams can act on the Best Next Action. Veracode Package Firewall uses AI analysis to block untrusted packages before they enter development pipelines, identifying and blocking 60 percent more malicious packages than competing solutions. Security teams tell SOFTPROM Distribution Gmbh they are drowning in vulnerability alerts while missing the risks that actually matter. Its latest innovations flip the script - instead of endless firefighting, teams can now prevent threats proactively and focus remediation efforts where they will have maximum business impact Derek Maki, Head of Product at Veracode Why this matters. For CIOs, CISOs, and procurement leaders, the shift from reactive alerting to preventive control changes the economics of application security. Blocking malicious packages at the gate reduces mean time to remediate, cuts operational overhead for SOC and AppSec teams, and supports compliance with DORA and similar frameworks. According to Gartner, organizations with a high-quality developer experience are 33 percent more likely to attain their business goals - making frictionless security a strategic advantage, not just a technical improvement. Technical details. * Veracode Risk Manager: Six new ASPM integrations including Wiz; up to 92% reduction in vulnerability remediation time. * Veracode Package Firewall: AI-driven blocking of malicious open-source packages; 60% more effective than competing solutions. * SCA and Malicious Package Detection: Neutralizes libraries harboring malicious code before ingestion. * AI-Assisted Login for DAST: Automates complex authentication flows, reducing script setup time by 50%. * Container and IaC Results: Centralized findings in the Veracode Platform for streamlined vulnerability management. * IDE and Git integrations: Visual Studio, IntelliJ IDEA, Eclipse, GitHub, GitLab, Azure DevOps - with 35% faster remediation. * Veracode Fix Usage Analytics: Dashboard tracking usage and CWEs addressed by IDE, project, and source file. Softprom and Veracode. Softprom is the official distributor of Veracode. Enterprises can access the full application risk management portfolio, technical enablement, and licensing support through Softprom. Request a consultation and pricing for the updated Veracode platform via Veracode. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.