LICENSEWARE

Veracode licensing

This article is an overview of how Veracode licenses its application security platform (Static Analysis, SCA, DAST, Fix and training products). It is not legal advice and does not replace the End User Assessment Agreement or an Order Form.

On This Page

Veracode licensing is the set of terms under which Veracode, Inc. sells access to its application security platform: static application security testing (Veracode Static Analysis), software composition analysis (Veracode SCA), dynamic testing of web applications and APIs (Veracode DAST), AI-generated code fixes (Veracode Fix), penetration testing services and developer security training (Security Labs and eLearning). The standard customer contract is the End User Assessment Agreement (EUAA). It grants a non-exclusive, non-transferable right to use the Solutions stated in an Order Form, during the Subscription Term, solely for the customer’s Internal Use.[1] Internal Use means customary internal business use, not use for compensation of any kind.[1] The Order Form states the Solutions ordered, the quantity, the fees and the Subscription Term.[1] How that quantity is measured depends on the product. Static Analysis is reported per application, using scan size in megabytes or, in tier contracts, application profiles.[2] API scanning in DAST is counted in target URLs.[4] Training products are sold as pools of learner seats.[6][7] For the general models, see subscription and consumption licensing.

Editions

Veracode does not publish a price list or edition matrix. The clearest public inventory of what can be bought is the Licensing column of the Veracode Platform user-role reference. It names a base Veracode Platform subscription, which most roles require. Product subscriptions sit on top of it: Veracode Static Analysis, Veracode SCA, Veracode DAST, Veracode EASM, Veracode Analytics, Veracode eLearning, Mitigation Proposal Reviews (MPR), Veracode Vendor Application Security Testing (VAST) and Veracode Greenlight.[3] Product permissions add their own requirements, for example a Veracode SCA subscription to view open-source results.[14]

Product family Subscriptions named in Veracode documents How usage is measured 
Static testing Veracode Static Analysis (Upload and Scan, Pipeline Scan, IDE scans)[3] Licences per application from the largest scan size; MB used; application profiles in the tier model (Standard, Small)[2] 
Open-source analysis Veracode SCA[3] Subscription; contract terms not published 
Dynamic testing Veracode DAST, with a 14-day free trial[3] Target URLs for API scans[4]; Dynamic Analysis scans also appear in consumption reports[2] 
Remediation Veracode Fix[13] Separate Fix licence 
Training Veracode Security Labs, Veracode eLearning[6][7] Learner seats 
Platform add-ons Analytics, EASM, MPR, VAST, Greenlight (deprecated)[3] Subscription; required for specific roles 

Product detail is in Veracode Static Analysis and SCA licensing and Veracode DAST, training and platform subscriptions.

Metrics

Veracode term Catalog row Where Veracode defines or counts it 
Application Application EUAA: a collection of logically related software components that perform a coordinated set of functions. The definition expressly includes virtual machines, containers, serverless functions, network resources and datastores.[1] 
MB purchased and MB used Megabytes of analysis size License Used Report: megabytes purchased in the contract and used in the subscription year.[2] 
Application profile Application profile (tier model) License Used Tier Model report: for Standard and Small, licences reflect the number of application profiles.[2] 
Target URL Target URL Each target URL represents a unique API server.[4] 
Contributing developer Contributing developer A member of an SCM project who contributed to a repository within the last 90 days. It is counted by the Veracode CLI.[5] 
Learner seat Security Labs learner seat; eLearning seat A seat pool for users with the Security Labs User role; seats per eLearning track.[6][7] 

Veracode’s public documents describe two commercial constructs. Application-based contracts are measured per application and per megabyte scanned. Tier contracts are measured per application profile. The consumption reports are built for both, and say that “your organization must use a licensing model that the reports support”.[2] Developer-based sizing also appears in the documentation. The Veracode CLI’s veracode repository report command lists unique contributing developers for each repository in an organisation’s source code management systems.[5] The public documents do not, however, publish the commercial terms of a developer-based subscription. The Order Form is the only place that states which measure a contract uses.

Counting / floors

Largest scan per year. The Largest Scan Report counts licences used per application. The count is the largest scan of each application in the subscription year, divided by the application size definition.[2] Read literally, rescanning the same application does not consume more licences unless a larger scan pushes it over a size boundary, and a single very large application can consume more than one licence. The application size definition itself is not published. Catalog: Licences used equal the largest scan per application divided by the application size definition.

Subscription years. In a multi-year contract the License Used Report has a row for each subscription year. Consumption metrics restart at 0 at the beginning of each year.[2] Catalog: Consumption restarts each subscription year; Multi-year subscription years.

Consumed means consumed. Deleting an application profile and its scan results does not return a consumed licence.[9] Some Static Analysis licences also cap the number of application profiles a customer can create.[10] Catalog: Deleting an application profile does not return a consumed licence; Some Static Analysis licences cap the number of application profiles.

Floors. No published document sets a minimum purchase. Quantities, and the size definition behind an application licence, are set on the Order Form.[1]

Virtualization & partitioning

Veracode is licensed by what is analysed, not by the hardware it runs on, so processor, core and partitioning rules do not apply. Virtualization matters only through the Application definition. Virtual machines, containers and serverless functions can each be designated as an Application for Assessment.[1] See virtualization and partitioning for the general topic.

Cloud / BYOL

The Solutions are delivered as software as a service from the Veracode Solution Platform. The customer supplies the systems and network needed to connect to it.[1] There is no bring-your-own-licence construct. If a customer buys through a Veracode authorized reseller, the Order Form may instead be entered into between Veracode and the reseller.[1]

Programs

Audits and compliance

The EUAA combines usage measurement with an obligation to pay for excess use. Veracode may limit or remove access for usage above the Order Form quantity, and the customer must pay fees for any excess use.[1] No more than once a year, on Veracode’s reasonable request, the customer must cooperate in measuring its usage and provide documentation of that measurement.[1] The platform supplies the evidence for this. Users with the Security Lead or Administrator role can generate the four license consumption reports under Analytics > Data Exports.[2] If those reports contain no automated data, the contract may have a legacy term that inhibits automation. In that case Veracode directs customers to their account manager.[2] Catalog: Use above the Order Form quantity is payable; Usage measurement at most once a year; Legacy contract terms can block automated consumption reporting. See software license audit and true-up.

A practical consequence follows. A licence manager tracking Veracode should export the Largest Scan Report each subscription year and compare its Licenses Used and MB Used totals with the Order Form. Under a tier contract, the License Used Tier Model report gives the same comparison per subscription SKU.[2] Test scans also count. Veracode’s own quickstart warns that scanning its sample application in a new profile uses a licence. This is described in Veracode Static Analysis and SCA licensing.

Contract terms

The EUAA’s restrictions matter for licence scope. Customers may not use the Solutions to provide services to or for the benefit of third parties, except as the Agreement permits. They may not perform or disclose benchmark tests. They may not use Remediations, Veracode’s suggested code changes, to train a large language model.[1] Reports outlive the subscription. The customer owns each Report and Remediation and holds a perpetual, worldwide licence to the Veracode Property contained in them, for Internal Use.[1] The Solutions themselves do not outlive it. When an Order Form expires, use of its Solutions must stop immediately. Assignment needs the other party’s prior written consent.[1] The full agreement is analysed in Veracode End User Assessment Agreement.

Out of scope

  • Prices and discounts. Veracode publishes no list prices.
  • Negotiated master agreements, government contract vehicles and marketplace private offers, which can replace the EUAA and were not retrievable.
  • The contractual application size definition and the terms of developer-based subscriptions, which appear only on Order Forms.
  • Veracode Risk Manager (Longbow), Package Firewall and Container Security in depth. Their licensing is not documented publicly beyond the base-subscription requirement for Package Firewall permissions.[14]
  • Penetration testing service packages, which are scoped per engagement.

References

  1. Veracode End User Assessment Agreement (20240610)s.1 definitions; s.3 licence grants; s.4 acceptable use, excess use and usage measurement; s.10 term; s.13 general. Version identifier 20240610. Catalog: End User Assessment Agreement (20240610)Effective 2024-06-10. Retrieved 2026-10-07.
  2. View and download reports (license consumption reports)License Used, Largest Scan, All Scans and License Used Tier Model reports. Last updated on Sep 2, 2026. Catalog: View and download reports (license consumption reports)Effective 2026-09-02. Retrieved 2026-10-07.
  3. UI user rolesLicensing column for each role. Last updated on Oct 2, 2026. Catalog: UI user rolesEffective 2026-10-02. Retrieved 2026-10-07.
  4. About API specification scansLicense to scan APIs; target URLs. Last updated on Jun 15, 2026. Catalog: About API specification scansEffective 2026-06-15. Retrieved 2026-10-07.
  5. veracode repository reportAbout contributing developers. Last updated on Apr 28, 2025. Catalog: veracode repository reportEffective 2025-04-28. Retrieved 2026-10-07.
  6. Manage Security Labs usersSecurity Labs licenses. Last updated on Oct 5, 2026. Catalog: Manage Security Labs usersEffective 2026-10-05. Retrieved 2026-10-07.
  7. eLearning subscriptions, tracks, and seat usageLast updated on May 6, 2026. Catalog: eLearning subscriptions, tracks, and seat usageEffective 2026-05-06. Retrieved 2026-10-07.
  8. Veracode Proof of Value Terms and Conditions (20240610)s.2 evaluation licence. Catalog: Proof of Value Terms and Conditions (20240610)Effective 2024-06-10. Retrieved 2026-10-07.
  9. Delete an application profileLast updated on Sep 2, 2026. Catalog: Delete an application profileEffective 2026-09-02. Retrieved 2026-10-07.
  10. Managing application profilesLast updated on Sep 2, 2026. Catalog: Managing application profilesEffective 2026-09-02. Retrieved 2026-10-07.
  11. Technical and Program SupportSupport hours and channels; undated. Catalog: Technical and Program Support pageRetrieved 2026-10-07.
  12. Development and Demonstration License AgreementVersion: September 11, 2024. Catalog: Development and Demonstration License AgreementEffective 2024-09-11. Retrieved 2026-10-07.
  13. Scan for VS CodeVeracode Fix licence prerequisite. Last updated on Sep 30, 2026. Catalog: Scan for VS CodeEffective 2026-09-30. Retrieved 2026-10-07.
  14. Custom user rolesLicensing prerequisites per permission. Last updated on Oct 2, 2026. Catalog: Custom user rolesEffective 2026-10-02. Retrieved 2026-10-07.
  15. Security Labs quickstart14-day free trial of Security Labs. Last updated on Sep 28, 2026. Catalog: Security Labs quickstartEffective 2026-09-28. Retrieved 2026-10-07.

See also

Catalog Rows Cited

11SKUs7Metrics7Rules7Programs

Esc