News & Events
| News |
| Press Releases |
| Events |
| Awards |
Veracode Launches World’s First Automated, Subscription-Based Security Audit for COTS Software and Outsourced Code DevelopmentBurlington, Mass., April 22, 2008 – Veracode Inc., the leading provider of on-demand application security testing solutions, today announced the first portfolio of subscription-based services to provide a clear and independent assessment of an organization’s external application security risk. Based on its on-demand code assurance platform, the Veracode SecurityReview® service now includes the ability for organizations to obtain a single view of security risks in their applications, whether those applications are purchased as commercial off-the-shelf software (COTS) or developed offshore. Application security has risen to the top of the agenda for security professionals striving to control their company’s overall risk profile. According to the Computer Emergency Response Team (CERT), more than 7,000 new vulnerabilities were discovered over the last year, with 92 percent of vulnerabilities found in software according to the National Institute of Standards and Technology. With organizations deploying an increasing number of complex applications – some developed internally, some offshore, some purchased off-the-shelf – the effort needed to manage risk becomes greater. Traditional approaches have focused on conducting costly and time-consuming manual penetration tests or using tools that typically require source code which usually isn’t available in mixed-code base environments or commercial applications. “Veracode offers a unique method for testing commercial-off-the-shelf software that fills an essential gap in our software security program enabling a more effective understanding of risk from commercial software along with information to manage this risk with our software vendors," said Jim Routh, CISO of Depository Trust & Clearing Corporation, who is participating in the “Five Keys to Effective Application Security and Secure Coding” keynote panel on April 22nd at Infosecurity Europe being held this week in London. Rhonda MacLean, Global Information Security Officer, Global Retail and Commercial Banking, Barclays Bank, who is also participating on the panel, further commented on the benefits of the Veracode service: “In a rapidly changing threat environment, Veracode’s technology and its software-as-a-service model have given us the flexibility to conduct rapid code review cycles, which is an obvious benefit for our customers.” “Enterprises are increasingly outsourcing the development of their applications and leveraging commercial software to run their business operations, but can’t outsource the security risk and liability associated with those applications,” said Diana Kelley, Partner at SecurityCurve. “Enterprises need effective ways to test and audit the risk associated with COTS and outsourced software when source code isn’t available.” Based on patented, static binary testing technology and dynamic web scanning analysis, Veracode’s SecurityReview is the industry’s first solution specifically designed to overcome the limitations of traditional tools and manual penetration tests:
The Veracode SecurityReview service portfolio is now comprised of the following on-demand services:
“With applications being the weakest link in the corporate security chain, organizations are increasingly demanding independent verification and validation of applications as part of their software release and acceptance criteria,” said Matt Moynahan, CEO at Veracode. “With Veracode, customers can now count on a single vendor delivering a comprehensive portfolio of on-demand services that delivers independent security audits for applications whether they are developed offshore or purchased off-the-shelf.”
Availability About Veracode Veracode is the world’s leader for on-demand application security testing solutions. Veracode SecurityReview is the industry’s first solution to use patented binary code analysis and dynamic web analysis to uniquely assess any application security threats, including vulnerabilities and malicious code. SecurityReview performs the only complete and independent security audit across any internally developed applications, third-party commercial off-the-shelf software and offshore code without exposing a company’s source code. Delivered as an on-demand service, Veracode delivers the simplest and most-cost effective way to implement security best practices, reduce operational cost and achieve compliance without requiring any hardware, software or training. Veracode has established a position as the market visionary and leader with awards that include recognition as a Gartner “Cool Vendor” 2008, Info Security Product Guide’s “Tomorrow’s Technology Today Award 2008,” Information Security “Readers’ Choice Award 2008,” AlwaysOn Northeast's "Top 100 Private Company 2008", NetworkWorld “Top 10 Security Company to Watch 2007,” and Dark Reading’s “Top 10 Hot Security Startups 2007.” Based in Burlington, Mass., Veracode is backed by .406 Ventures, Atlas Venture and Polaris Venture Partners. For more information, visit www.veracode.com.
Contacts: |
|||||||||||||

