Contact:
Kate Munro
Veracode, Inc.
781-425-6040 ext. 296
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it

Veracode Selects SPI Dynamics™ WebInspect for Industry's First On-Demand Application Security Service Providing Static and Dynamic Application Analysis

 

RSA Conference 2007 San Francisco, CA, February 5, 2007 — Veracode, Inc., the industry's first provider of automated, on-demand application security solutions, today announced it has selected SPI Dynamics' market leading application security testing solution, WebInspect, to provide customers with integrated dynamic testing capabilities as part of the company's on-demand service platform, SecurityReview™. This best of breed combination of static binary testing and dynamic analysis of software applications delivers a unique solution to help organizations improve software security using complementary methodologies — without the release of source code or disruption to the software development lifecycle (SDLC).

Veracode SecurityReview solutions, based on the company's patented binary analysis technology, allow organizations to discover and prioritize security flaws in software automatically, without releasing valuable source code. SPI Dynamics' WebInspect product is the market leader in dynamic web application security testing. By integrating WebInspect into SecurityReview, Veracode will be able to offer dynamic run-time analysis testing as part of their on-demand service platform. The integration provides the broadest coverage of automated testing techniques through a single, trusted service.

Veracode and SPI Dynamics both understand that application security requires multiple technologies and code testing methodologies to ensure appropriate levels of security for applications, said Matthew Moynahan, president and chief executive officer of Veracode, Inc. By delivering best of breed static binary testing and dynamic run-time analysis through a single on-demand services platform, Veracode can deliver a comprehensive, automated code security solution while maintaining a positive user experience.

To enable a security services provider, web application security testing software must be highly automated, scalable, fast, comprehensive and accurate, said Brian Cohen, president and chief executive officer for SPI Dynamics. As the market leader in web application security testing software, SPI Dynamics is the only partner of choice for application security service providers looking for a scalable, automated solution. SPI Dynamics continues to work with innovative security service providers to deliver the most comprehensive web application security testing, and we are pleased to have been chosen by Veracode to add dynamic testing to their solutions.

Different methodologies are best suited for identifying software vulnerabilities at different stages of the SDLC. This integration allows customers to take advantage of multiple technologies throughout their development lifecycle, as well as a unique opportunity to choose binary and dynamic testing via an on-demand service. Veracode's intuitive user interface allows users to submit compiled applications and view all security flaws. Through the online service, users can select multiple testing methodologies based on the application's required assurance level. Development teams have the ability to request analysis when required and to review results without requiring any change to the current development process or investment in software or hardware.

About Veracode Veracode is the industry's first provider of automated, on-demand application security solutions.Created by a world-class team of application security experts from @stake, Guardent, ISS, VeriSign and Symantec, the company delivers services to identify software flaws introduced through coding errors or malicious intent. Veracode's core service, SecurityReview™ uses patented binary code analysis that is uniquely able to inspect entire application inventories, including components, and does not require companies to give up their valuable source code. Enterprises can now protect their intellectual property while preventing attacks allowed by vulnerabilities in applications.

As the most accurate and comprehensive solution, Veracode makes it simple and cost-effective to implement application security best practices and reduce operational costs related to manual reviews. Whether a company is developing applications internally, purchasing software or integrating code from partners, Veracode's SecurityReview™ provides insight to the security level of your applications. Outsourcing code analysis to Veracode is the easiest way to secure your software. With a pragmatic approach to application security, Veracode helps you fix what matters most to your business.

Based in Burlington, Mass., Veracode is backed by .406 Ventures, Atlas Venture and Polaris Venture Partners. http://www.veracode.com/