# Veracode: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 36 judge labels across 2 categories by 12 of 12 models. Page: https://it-ai-index.com/vendors/veracode/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Static application security testing | 2% | 8 | 41% | 34 |
| Software composition analysis | 0% | 34 | 0% | 2 |

## What the models said for it

- "A cloud-based veteran known for stability and deep static/dynamic hybrid analysis." (Qwen 3.7 Flash, SAST)
- "I'd recommend Veracode if you want the safest default choice" (Perplexity Sonar, SAST)
- "Best overall enterprise choice: Checkmarx or Veracode" (Perplexity Sonar, SAST)
- "Checkmarx, Veracode, or Fortify are recommended if enterprise governance, compliance reporting, and mature procurement paths matter most." (Claude Haiku 4.5, SAST)

## And against it

- "Avoid legacy, binary-upload scanners... historically pioneered by tools like Veracode)... a major friction point for modern, fast-paced DevSecOps teams." (Gemini 3.5 Flash, SAST)
- "Checkmarx One / Fortify / Vercode: ... They offer little value to small teams and are expensive to maintain." (Qwen 3.7 Flash, SAST)
- "traditional enterprise legacy tools (like Checkmarx or Veracode) are usually too expensive, slow, and noisy" (Gemini 3.5 Flash, SAST)
- "they are rarely the right fit for mid-market B2B companies" (Gemini 3.5 Flash, SAST)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
