Updated:
Veracode
Veracode is a asset manager based in Burlington, founded 2006; the Altss profile covers its classification, headquarters, registration, AUM band, and key...
Veracode
Manage application security risks effectively with Veracode's Application Risk Management platform, built for today's AI-driven world.
General information
Firm type
Asset Manager
Year founded
2006
Location
Region
North America
Country
United States
City
Burlington
Corporate office
65 Blue Sky Drive, Burlington, MA 01803, United States
Additional offices
London, United Kingdom
Principals
Brian Roche
Chief Executive Officer
Chris Wysopal
Founder and Chief Security Evangelist
Christien Rioux
Co-Founder
Simon Adell
Chief Financial Officer
Anthony Barkley
Chief Strategy Officer
Karen Buffo
Chief Marketing Officer
Diana Bushard
General Counsel
Sector focus
Frequently asked questions
Who runs investment decisions at Veracode?
Veracode is not an investment firm; it is a privately held application-security platform company. Strategic and financial decisions are made by CEO Brian Roche and the executive leadership team, with oversight from its private-equity backers.
How is Veracode different from standard SAST or DAST scanning tools?
Veracode operates a platform rather than a point tool, combining static, dynamic, and software-composition analysis with AI-driven remediation guidance across the full development lifecycle. It also maintains a proprietary vulnerability database built from two decades of scanning data, which it uses to train its detection and fix-recommendation engines.
What is the significance of the L0pht connection to the company's current strategy?
Co-founder Chris Wysopal was a member of L0pht, a hacker collective that testified before Congress in 1998 about software security weaknesses. He continues as Chief Security Evangelist, a role that connects Veracode's commercial platform to the public policy and practitioner community that emerged from that era.
Does Veracode provide security coverage for AI-generated code?
Yes. The firm markets specific capabilities to scan and remediate vulnerabilities in code produced by AI coding assistants, a segment it calls the 'AI-coding era.' This functionality is integrated into the broader application-risk management platform.
Who owns Veracode now, and how has the ownership structure evolved?
Veracode was originally independent, acquired by CA Technologies in 2017 for $614 million, and then spun out as a standalone business backed by Thoma Bravo in 2018. It is currently held by private-equity investors, with Thoma Bravo having sold a majority stake to TA Associates in 2022 (per historical M&A records; not verified in provided firm materials).
What industries or customer segments does Veracode primarily serve?
The firm serves over 2,400 organizations globally, with case studies highlighting insurance (HDI Global SE), healthcare technology (Azalea Health), and cloud services (multi-cloud environments using Veracode Fix). It sells to both security teams and development organizations, with executive governance features targeting C-level buyers.
How does Veracode source threat intelligence, and is it shared with the community?
Veracode derives threat intelligence from its proprietary database, which is built from scanning trillions of lines of customer code. The firm publishes an annual State of Software Security report and periodic research such as its GenAI Code Security Update, which shares aggregated findings with the broader industry.
Profile maintained by Altss using OSINT (open-source intelligence), regulatory filings, licensed data partners, and verified direct submissions. Read the methodology. Last updated: . Continuous refresh with full update cycles at least every 30 days.
Need institutional-grade insight on asset managers?
Altss delivers:
Prefer a guided tour?
We’ll walk you through: