Veracode licensing is the set of terms under which Veracode, Inc. sells access to its application security platform: static application security testing (Veracode Static Analysis), software composition analysis (Veracode SCA), dynamic testing of web applications and APIs (Veracode DAST), AI-generated code fixes (Veracode Fix), penetration testing services and developer security training (Security Labs and eLearning). The standard customer contract is the End User Assessment Agreement (EUAA). It grants a non-exclusive, non-transferable right to use the Solutions stated in an Order Form, during the Subscription Term, solely for the customer’s Internal Use.[1] Internal Use means customary internal business use, not use for compensation of any kind.[1] The Order Form states the Solutions ordered, the quantity, the fees and the Subscription Term.[1] How that quantity is measured depends on the product. Static Analysis is reported per application, using scan size in megabytes or, in tier contracts, application profiles.[2] API scanning in DAST is counted in target URLs.[4] Training products are sold as pools of learner seats.[6][7] For the general models, see subscription and consumption licensing.
Editions
Veracode does not publish a price list or edition matrix. The clearest public inventory of what can be bought is the Licensing column of the Veracode Platform user-role reference. It names a base Veracode Platform subscription, which most roles require. Product subscriptions sit on top of it: Veracode Static Analysis, Veracode SCA, Veracode DAST, Veracode EASM, Veracode Analytics, Veracode eLearning, Mitigation Proposal Reviews (MPR), Veracode Vendor Application Security Testing (VAST) and Veracode Greenlight.[3] Product permissions add their own requirements, for example a Veracode SCA subscription to view open-source results.[14]
| Product family | Subscriptions named in Veracode documents | How usage is measured |
|---|---|---|
| Static testing | Veracode Static Analysis (Upload and Scan, Pipeline Scan, IDE scans)[3] | Licences per application from the largest scan size; MB used; application profiles in the tier model (Standard, Small)[2] |
| Open-source analysis | Veracode SCA[3] | Subscription; contract terms not published |
| Dynamic testing | Veracode DAST, with a 14-day free trial[3] | Target URLs for API scans[4]; Dynamic Analysis scans also appear in consumption reports[2] |
| Remediation | Veracode Fix[13] | Separate Fix licence |
| Training | Veracode Security Labs, Veracode eLearning[6][7] | Learner seats |
| Platform add-ons | Analytics, EASM, MPR, VAST, Greenlight (deprecated)[3] | Subscription; required for specific roles |
Product detail is in Veracode Static Analysis and SCA licensing and Veracode DAST, training and platform subscriptions.
Metrics
| Veracode term | Catalog row | Where Veracode defines or counts it |
|---|---|---|
| Application | Application | EUAA: a collection of logically related software components that perform a coordinated set of functions. The definition expressly includes virtual machines, containers, serverless functions, network resources and datastores.[1] |
| MB purchased and MB used | Megabytes of analysis size | License Used Report: megabytes purchased in the contract and used in the subscription year.[2] |
| Application profile | Application profile (tier model) | License Used Tier Model report: for Standard and Small, licences reflect the number of application profiles.[2] |
| Target URL | Target URL | Each target URL represents a unique API server.[4] |
| Contributing developer | Contributing developer | A member of an SCM project who contributed to a repository within the last 90 days. It is counted by the Veracode CLI.[5] |
| Learner seat | Security Labs learner seat; eLearning seat | A seat pool for users with the Security Labs User role; seats per eLearning track.[6][7] |
Veracode’s public documents describe two commercial constructs. Application-based contracts are measured per application and per megabyte scanned. Tier contracts are measured per application profile. The consumption reports are built for both, and say that “your organization must use a licensing model that the reports support”.[2] Developer-based sizing also appears in the documentation. The Veracode CLI’s veracode repository report command lists unique contributing developers for each repository in an organisation’s source code management systems.[5] The public documents do not, however, publish the commercial terms of a developer-based subscription. The Order Form is the only place that states which measure a contract uses.
Counting / floors
Largest scan per year. The Largest Scan Report counts licences used per application. The count is the largest scan of each application in the subscription year, divided by the application size definition.[2] Read literally, rescanning the same application does not consume more licences unless a larger scan pushes it over a size boundary, and a single very large application can consume more than one licence. The application size definition itself is not published. Catalog: Licences used equal the largest scan per application divided by the application size definition.
Subscription years. In a multi-year contract the License Used Report has a row for each subscription year. Consumption metrics restart at 0 at the beginning of each year.[2] Catalog: Consumption restarts each subscription year; Multi-year subscription years.
Consumed means consumed. Deleting an application profile and its scan results does not return a consumed licence.[9] Some Static Analysis licences also cap the number of application profiles a customer can create.[10] Catalog: Deleting an application profile does not return a consumed licence; Some Static Analysis licences cap the number of application profiles.
Floors. No published document sets a minimum purchase. Quantities, and the size definition behind an application licence, are set on the Order Form.[1]
Virtualization & partitioning
Veracode is licensed by what is analysed, not by the hardware it runs on, so processor, core and partitioning rules do not apply. Virtualization matters only through the Application definition. Virtual machines, containers and serverless functions can each be designated as an Application for Assessment.[1] See virtualization and partitioning for the general topic.
Cloud / BYOL
The Solutions are delivered as software as a service from the Veracode Solution Platform. The customer supplies the systems and network needed to connect to it.[1] There is no bring-your-own-licence construct. If a customer buys through a Veracode authorized reseller, the Order Form may instead be entered into between Veracode and the reseller.[1]
Programs
- Proof of Value. An evaluation licence for a period not exceeding the number of days the parties agree.[8]
- DAST free trial and Security Labs free trial. Both trials last 14 days.[3][15] They are covered in Veracode DAST, training and platform subscriptions.
- Third-party application testing. Customers can have vendor-owned applications assessed. The vendor owns the detailed Report.[1] Consumption reports distinguish SDLC and third-party licence types.[2]
- Enhanced Support. Support response times vary by support tier.[11]
- Development and Demonstration License. Technology partners receive a royalty-free licence to build and demonstrate integrations. The licence excludes internal production use.[12]
Audits and compliance
The EUAA combines usage measurement with an obligation to pay for excess use. Veracode may limit or remove access for usage above the Order Form quantity, and the customer must pay fees for any excess use.[1] No more than once a year, on Veracode’s reasonable request, the customer must cooperate in measuring its usage and provide documentation of that measurement.[1] The platform supplies the evidence for this. Users with the Security Lead or Administrator role can generate the four license consumption reports under Analytics > Data Exports.[2] If those reports contain no automated data, the contract may have a legacy term that inhibits automation. In that case Veracode directs customers to their account manager.[2] Catalog: Use above the Order Form quantity is payable; Usage measurement at most once a year; Legacy contract terms can block automated consumption reporting. See software license audit and true-up.
A practical consequence follows. A licence manager tracking Veracode should export the Largest Scan Report each subscription year and compare its Licenses Used and MB Used totals with the Order Form. Under a tier contract, the License Used Tier Model report gives the same comparison per subscription SKU.[2] Test scans also count. Veracode’s own quickstart warns that scanning its sample application in a new profile uses a licence. This is described in Veracode Static Analysis and SCA licensing.
Contract terms
The EUAA’s restrictions matter for licence scope. Customers may not use the Solutions to provide services to or for the benefit of third parties, except as the Agreement permits. They may not perform or disclose benchmark tests. They may not use Remediations, Veracode’s suggested code changes, to train a large language model.[1] Reports outlive the subscription. The customer owns each Report and Remediation and holds a perpetual, worldwide licence to the Veracode Property contained in them, for Internal Use.[1] The Solutions themselves do not outlive it. When an Order Form expires, use of its Solutions must stop immediately. Assignment needs the other party’s prior written consent.[1] The full agreement is analysed in Veracode End User Assessment Agreement.
Out of scope
- Prices and discounts. Veracode publishes no list prices.
- Negotiated master agreements, government contract vehicles and marketplace private offers, which can replace the EUAA and were not retrievable.
- The contractual application size definition and the terms of developer-based subscriptions, which appear only on Order Forms.
- Veracode Risk Manager (Longbow), Package Firewall and Container Security in depth. Their licensing is not documented publicly beyond the base-subscription requirement for Package Firewall permissions.[14]
- Penetration testing service packages, which are scoped per engagement.