Veracode DAST, training and platform subscriptions are the Veracode products that are not counted by application scan size. Veracode DAST tests running web applications and APIs. Veracode Security Labs and Veracode eLearning provide developer security training. A group of platform add-ons (Analytics, External Attack Surface Management, Mitigation Proposal Reviews, Vendor Application Security Testing and Enhanced Support) enables specific roles and services. All are sold under the Veracode End User Assessment Agreement, with quantities on the Order Form.[15] For the overview, see Veracode licensing.
Editions
| Subscription | What Veracode documents | Unit |
|---|---|---|
| Veracode DAST (Dynamic Analysis licence) | Scans of web applications and APIs. Quick scan and Full scan (Enterprise mode) scopes.[5] | Target URLs for API scanning; scan capacity for concurrency[1] |
| Veracode Security Labs | Hands-on secure coding labs, used through the Veracode Platform or a standalone account[7] | Learner seats[6] |
| Veracode eLearning | Two course tracks, eLearning and eLearning Awareness[9] | Seats per track[9] |
| Veracode Analytics | Custom analytics reports and dashboards[3] | Subscription |
| Veracode EASM | External attack surface management[3] | Subscription |
| Mitigation Proposal Reviews | Review of proposed mitigations[3] | Subscription |
| Vendor Application Security Testing | Third-party (vendor) scan requests. Might not be available for all organizations.[3] | Subscription |
| Veracode Greenlight | IDE scanning. Veracode lists it as deprecated.[3] | Individual subscription |
Most of these sit on a base Veracode Platform subscription. Veracode’s custom role reference repeatedly says that permissions require it.[12]
Metrics
Target URL (DAST). Using DAST or Dynamic Analysis requires a Dynamic Analysis licence. To scan APIs from specifications or Postman Collections, Veracode counts the target URLs in that licence. Each target URL equates to a unique API server defined in the specifications.[1] The API specification documentation says the same, under a heading on the licence to scan APIs.[2] Catalog: Each API server scanned deducts a target URL.
Scan capacity (DAST). A separate scan capacity subscription determines how many DAST or Dynamic Analysis scans can run concurrently.[1] The public documentation does not give the default capacity.
Learner seat (Security Labs). An organisation has a license pool of a set number of learner seats. Only users with the Security Labs User role consume a seat.[6] Catalog: Each Security Labs User role assignment consumes a seat; Only Security Labs learners consume seats.
eLearning seat. Each eLearning subscription maps to a track. An organisation that subscribes to both tracks has a separate seat allocation for each, and a learner can be assigned to only one track.[9]
Counting / floors
Each API server counts. During a specification scan, Veracode detects the target API server and deducts it from the target URLs available. Scanning the same specification against a second server deducts a second target URL.[2][1] Test, staging and production instances of one API can therefore consume three target URLs. Catalog: Same specification against a second server uses a second target URL. Veracode directs customers to their sales representative to obtain or change a Dynamic Analysis licence.[1]
Dynamic scans in consumption reports. The license consumption reports cover scan activity for both Static Analysis and Dynamic Analysis.[14]
Security Labs: assignment consumes. Every assignment of the Security Labs User role consumes a licence, and removing a Security Labs user frees one. To move a seat from one user to another, the administrator disables the user whose seat is to be moved.[6]
eLearning: access consumes. Assigning a track allocates a seat, but the seat is not used until the learner accesses a course. Until then it can be reassigned. Once a learner launches a course, the seat cannot be removed until the end of the subscription period.[9] A three-year subscription is usually divided into three subscription years. A seat in use can be removed in mid-year only if the learner leaves the organisation. With Auto Extend off, seats can be reallocated at the end of a subscription year.[9] Catalog: An eLearning seat is used only when a course is accessed; An eLearning seat in use stays with the learner for the subscription period.
Auto Extend. Auto Extend is on by default when a learner is assigned a track, and it renews that learner’s seat when the subscription renews. If the organisation reduces its seat count between subscriptions while learners have Auto Extend on, eLearning locks the course tracks for all learners. Access returns only when the number of Auto Extend learners is brought within the available seats.[9] Catalog: Reducing eLearning seats with Auto Extend on locks all tracks. This is the main renewal trap for a licence manager reducing a training subscription.
Floors. No minimum quantities are published for any of these products.
Virtualization & partitioning
DAST counts API servers, not the machines behind them. The EUAA lets a web Application be supplied for Assessment by providing its URL.[15] Training seats are user-based. Neither is affected by virtualization.
Cloud / BYOL
All of these products are delivered from the Veracode Platform. Targets must be externally accessible to Veracode for scanning.[1] Veracode recommends scanning a test or staging system rather than production for invasive scans such as Full scan (Enterprise mode).[5] When creating a target, the user must certify the right to scan the target URL.[4] Under the EUAA, Veracode excludes liability for harm to customer systems arising from penetration tests and simulated attacks.[15]
Programs
- DAST free trial. The free trial is a 14-day trial for DAST, with one per free trial organisation.[3] It is started from the Veracode Platform sign-in page.[4] Catalog: DAST free trial lasts 14 days.
- Security Labs free trial. A 14-day free trial that does not require a Veracode account.[7] The free Security Labs Community Edition was deprecated on 2026-07-31. Veracode now points former users to the trial.[8] Catalog: Security Labs Community Edition was deprecated.
- Enhanced Support. Consultation calls with a Veracode Application Security Consultant require an Enhanced Support subscription. Next-day consultations require a separate next-day consultation subscription.[10] Support response times vary by support tier.[11] Catalog: Consultation calls require Enhanced Support.
- Third-party application testing. Vendors that receive a third-party scan request must accept it before submitting a scan. The Vendor Manager role requires a VAST subscription.[3]
Audits and compliance
Training seat usage is visible in the platform. The eLearning Subscription Details page shows total seats, seats assigned, seats used and learners set to Auto Extend for each track.[9] For DAST, the number of target URLs used should be reconciled with the licence before new API environments are added. Each new server counts separately.[2] Automation against the platform is also limited by rate rather than by licence: all REST APIs are limited to 500 calls per minute per IP address.[13] Catalog: REST APIs are limited to 500 calls per minute per IP address. See software license audit and named user licensing.
Out of scope
- Penetration testing services, which are scoped per engagement.
- The default scan capacity and target URL quantities in individual contracts.
- Prices for training seats and add-ons, which Veracode does not publish.