{
  "generated_from": "https://saas-ranking.com/vulnerability-management/veracode",
  "disclaimer": "Every result describes what we found at the addresses we checked on the date given. It is not a statement about what the vendor does or does not have. The score is a public transparency score, not a product or security rating.",
  "snapshot": "r7.74650",
  "snapshot_run": 7,
  "score_version": "v1",
  "vendor": {
    "name": "Veracode",
    "domain": "veracode.com"
  },
  "category": {
    "slug": "vulnerability-management",
    "name": "Vulnerability management"
  },
  "score": 43,
  "band": "D",
  "measured": 12,
  "of": 12,
  "criteria": [
    {
      "key": "dpa",
      "name": "Data processing agreement",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/legal/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/legal/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/legal/data-processing-addendum",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/legal/gdpr",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/trust/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/privacy/dpa",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.480Z"
    },
    {
      "key": "subprozessoren",
      "name": "Subprocessor list",
      "weight": 3,
      "result": "found",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "addresses_checked": [
        {
          "url": "https://veracode.com/legal/subprocessors",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.484Z"
    },
    {
      "key": "datenregion",
      "name": "Data location stated",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/security",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/trust",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/legal/privacy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/privacy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/privacy-policy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/compliance",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/legal/privacy-policy",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.492Z"
    },
    {
      "key": "statusseite",
      "name": "Status page with history",
      "weight": 2,
      "result": "found",
      "source_url": "https://status.veracode.com/",
      "addresses_checked": [
        {
          "url": "https://status.veracode.com/",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.494Z"
    },
    {
      "key": "preise",
      "name": "Public pricing",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/pricing",
          "result": "reached and rendered, no match"
        },
        {
          "url": "https://veracode.com/pricing/",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/plans",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/en/pricing",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/pricing-plans",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.494Z"
    },
    {
      "key": "zertifizierungen",
      "name": "Certifications named",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.veracode.com/resources/whitepapers/compliance-first-appsec-posture/",
      "addresses_checked": [
        {
          "url": "https://veracode.com/security",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/trust",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/trust-center",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/compliance",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.495Z"
    },
    {
      "key": "sla",
      "name": "Uptime SLA with a figure",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/legal/sla",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/sla",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/legal/service-level-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/trust/sla",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/uptime",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/legal/uptime-sla",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.498Z"
    },
    {
      "key": "transport",
      "name": "HTTPS enforced with HSTS",
      "weight": 2,
      "result": "found",
      "source_url": "https://veracode.com/",
      "addresses_checked": [
        {
          "url": "http://veracode.com/",
          "result": "redirects to https://www.veracode.com/"
        },
        {
          "url": "https://veracode.com/",
          "result": "HSTS max-age=31536000"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.498Z"
    },
    {
      "key": "tracker_vor_einwilligung",
      "name": "No third-party tracking before consent",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/",
          "result": "third-party requests before any interaction: bam.nr-data.net, cdn.cookielaw.org, cdnjs.cloudflare.com, fonts.googleapis.com, fonts.gstatic.com, geolocation.onetrust.com, js-agent.newrelic.com, p.typekit.net, use.typekit.net, www.googletagmanager.com"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.500Z"
    },
    {
      "key": "security_txt",
      "name": "security.txt (RFC 9116)",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/.well-known/security.txt",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.503Z"
    },
    {
      "key": "subprozessor_meldung",
      "name": "Notice before subprocessors change",
      "weight": 2,
      "result": "found",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "addresses_checked": [
        {
          "url": "https://veracode.com/legal/subprocessors",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.504Z"
    },
    {
      "key": "datenschutzkontakt",
      "name": "Named privacy contact",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://veracode.com/legal/privacy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/privacy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/privacy-policy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/legal/privacy-policy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/legal/privacy-notice",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://veracode.com/trust/privacy",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://veracode.com/datenschutz",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-05T05:16:50.505Z"
    }
  ],
  "details": [
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "cloudflare.com",
      "subject": null,
      "quote": "cdnjs.cloudflare.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "cookielaw.org",
      "subject": null,
      "quote": "cdn.cookielaw.org",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googleapis.com",
      "subject": null,
      "quote": "fonts.googleapis.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googletagmanager.com",
      "subject": null,
      "quote": "www.googletagmanager.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "gstatic.com",
      "subject": null,
      "quote": "fonts.gstatic.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "newrelic.com",
      "subject": null,
      "quote": "js-agent.newrelic.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "nr-data.net",
      "subject": null,
      "quote": "bam.nr-data.net",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "onetrust.com",
      "subject": null,
      "quote": "geolocation.onetrust.com",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "typekit.net",
      "subject": null,
      "quote": "p.typekit.net, use.typekit.net",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.502Z"
    },
    {
      "key": "hsts_frist",
      "name": "HSTS max-age",
      "value": "31536000",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.499Z"
    },
    {
      "key": "hsts_option",
      "name": "HSTS option",
      "value": "include-subdomains",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.499Z"
    },
    {
      "key": "hsts_option",
      "name": "HSTS option",
      "value": "preload",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://veracode.com/",
      "measured_on": "2026-09-05T05:16:50.499Z"
    },
    {
      "key": "meldefrist_tage",
      "name": "Subprocessor notice period",
      "value": "30",
      "subject": null,
      "quote": "om you sent to [address]@Veracode.com within 30 days of receiving notice of Veracode appointing a new subprocessor to this list, you will be deemed to have approved the use of such subprocessor.",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.504Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "amazon-web-services",
      "subject": null,
      "quote": "Amazon Web Services",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "okta",
      "subject": null,
      "quote": "Okta",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "salesforce",
      "subject": null,
      "quote": "Salesforce",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "segment",
      "subject": null,
      "quote": "Segment",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "snowflake",
      "subject": null,
      "quote": "Snowflake",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "subprozessor",
      "name": "Subprocessor named",
      "value": "twilio",
      "subject": null,
      "quote": "Twilio",
      "source_url": "https://www.veracode.com/legal-privacy/subprocessors-notification/",
      "measured_on": "2026-09-05T05:16:50.489Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27001",
      "subject": "erwaehnt",
      "quote": "o a single source of truth that maps technical evidence directly to regulatory controls like SOC 2, ISO 27001, and PCI DSS.",
      "source_url": "https://www.veracode.com/resources/whitepapers/compliance-first-appsec-posture/",
      "measured_on": "2026-09-05T05:16:50.497Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "pci-dss",
      "subject": "erwaehnt",
      "quote": "ce of truth that maps technical evidence directly to regulatory controls like SOC 2, ISO 27001, and PCI DSS.",
      "source_url": "https://www.veracode.com/resources/whitepapers/compliance-first-appsec-posture/",
      "measured_on": "2026-09-05T05:16:50.497Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "soc-2",
      "subject": "erwaehnt",
      "quote": "SCA into a single source of truth that maps technical evidence directly to regulatory controls like SOC 2, ISO 27001, and PCI DSS.",
      "source_url": "https://www.veracode.com/resources/whitepapers/compliance-first-appsec-posture/",
      "measured_on": "2026-09-05T05:16:50.497Z"
    }
  ]
}