Contact:
Kate Munro
Veracode, Inc.
781-425-6040 ext. 296
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it

Veracode Partners with Leviathan Security Group and Virtual Security Research

New Alliances Enhance Veracode's Automated SecurityReview Offerings

Burlington, Mass., – February 6, 2007 Veracode, Inc., provider of the industry's first automated, on-demand, application security code reviews, today announced two additions to its partner network. New alliances with Leviathan Security Group and Virtual Security Research (VSR) will augment Veracode's field research efforts and allow Veracode to integrate manual code review and penetration testing to its suite of automated application security services. Organizations can now implement a complete suite of application security analysis for their application portfolio through a single, trusted partner.

Veracode's unique, on-demand platform integrates multiple testing methodologies to ensure appropriate levels of security analysis for different applications. By partnering with Leviathan and VSR, Veracode now can augment its automated binary analysis service with manual penetration testing and source code reviews for highest-assurance applications. Combined with Veracode's SecurityReviewâ„¢ solutions, these partnerships allow Veracode to deliver the most comprehensive application security services and deploy the right amount of application security testing for a specific application based on business needs.

“At Veracode, we understand that different applications require different levels of security testing. High assurance applications may require additional code testing methodologies, including manual techniques, to ensure appropriate levels of security, said Matthew Moynahan, President and Chief Executive Officer of Veracode, Inc. "Our partnerships with Leviathan and VSR provide us with close relationships with some of the world's top security researchers. In turn, our customers can now access all the security testing required for their specific needs, through a single, trusted partner".

Leviathan Security Group was formed in 2003 by a group of distinguished security professionals. The Company focuses exclusively on application security services and specializes in black box application security assessments and code reviews. Years of industry experience coupled with hundreds of application security assessments gives Leviathan Security Group experience and deep security insight.

"Working with Veracode's world-class security experts will allow us to combine resources and address a broader range of application security issues", said Frank Heidt, CEO of Leviathan Security Group. The integration of our field work with Veracode's automated technology helps our customers secure their applications and better equips us to perform tests, conduct assessments and ultimately identify security issues that impact business.

VSR's team of security professionals are experts in the realm of application and information security, identifying vulnerabilities and areas of increased risk exposure within applications, and subsequently helping firms to reduce and mitigate this risk through a cohesive security program integrated throughout the Software Development Life-Cycle (SDLC). VSR's application security services include design & architecture reviews, security code reviews, penetration testing and training. VSR experience extends beyond application security consulting to areas of new research in order to maintain the competitive edge. Many of VSR's security professionals participate in this effort by conducting independent security research in leading commercial and open source applications and are credited with the identification and responsible disclosure of these vulnerabilities.

"We are excited to combine forces with Veracode and extend our services to include the Veracode SecurityReview services. These solutions fit our model and integrate well within the SDLC for many of our clients", said George Gal, Chief Security Consultant at VSR.This partnership allows us to focus our expertise on security issues that require a high level of assurance through manual reviews, and work closely with Veracode on field research projects. Our customers, and Veracode's, will benefit from our combined expertise and improve the security of a greater range of application assurance levels. Like VSR, Veracode takes a very pragmatic and business-centric approach to solving the application security problem, and this will help our customers fix what matters most to their business.

About Leviathan Security Group
Formed by recognized security industry leaders with proven track records (including former principals of @stake, Guardent, Symantec, and Foundstone), Leviathan Security Group, Inc. is a full-service information security consultancy specializing in application security, risk management, and compliance.

Today's security marketplace demands integrated solutions rather than a patchwork of commodity point fixes. Leviathan brings more than 100 years of combined security expertise to bear on our customers' most challenging scenarios, and applies it via a hands-on, solutions-oriented delivery model. Our expertise spans the entire lifecycle of information security, from program development and implementation, awareness and training, assessment and monitoring, to incident response and forensics.

Leviathan's technical acumen is unsurpassed, as demonstrated by our customers' loyalty, our extensive published research, and our contributions to well-respected security community projects. Our unique capabilities drive scaleable, technology-enhanced consulting services, integrated within a field-tested methodology for project management and quality assurance overseen directly by the executive team. It's clear why Fortune 100 clients rely on us for trusted, independent security risk advice.

Leviathan Security Group's offices are located in Seattle, WA and Denver, CO. We can be found on the Internet at http://www.leviathansecurity.com, or This e-mail address is being protected from spam bots, you need JavaScript enabled to view it .

About Virtual Security Research
Virtual Security Research is focused on providing quality information security consulting services. With clients in the financial services, manufacturing, service provider and commercial software sectors, VSR has demonstrated the risk / reward benefit and quantifying risk in business terms through its custom assessment methodology. VSR's security services are often tightly coupled with our clients' Software Development Life-Cycle to reduce risk in a cost effective manner and improve the overall security posture over time. VSR's services include: application penetration assessments, security code reviews, design & architecture reviews, training and incident response / forensic services.

The VSR competitive advantage includes a team of recognized security specialists and researchers with niche focus areas across the application security spectrum. The team works closely with clients to identify vulnerabilities and develop a remediation strategy to measurably reduce organizational security risk over time.

The team of VSR security professionals has a significant background in computer information security with a concentration on application security. Many of the founders have over 10 years of experience in information security research and consulting. The firm's security specialists are comprised of experts from leading security organizations including @stake, Symantec and QinetiQ Trusted Information Management.

For more information on Virtual Security Research, please visit us on the web: http://www.vsecurity.com/.

About Veracode
Veracode is the industry's first provider of automated, on-demand application security solutions. Created by a world-class team of application security experts from @stake, Guardent, ISS, VeriSign and Symantec, the company delivers services to identify software flaws introduced through coding errors or malicious intent. Veracode's core service, SecurityReview uses patented binary code analysis that is uniquely able to inspect entire application inventories, including components, and does not require companies to expose their valuable source code. Enterprises can now protect their intellectual property while preventing attacks allowed by vulnerabilities in applications.

As the most accurate and comprehensive solution, Veracode makes it simple and cost-effective to implement application security best practices and reduce operational costs related to manual reviews. Whether a company is developing applications internally, purchasing software or integrating code from partners, Veracode's SecurityReview provides insight to the security level of your applications. Outsourcing code analysis to Veracode is the easiest way to secure your software. With a pragmatic approach to application security, Veracode helps you fix what matters most to your business.

Based in Burlington, Mass., Veracode is backed by .406 Ventures, Atlas Venture and Polaris Venture Partners. http://www.veracode.com/