Executive Summary
Secretaria de Estado de Fazenda de Minas Gerais (SEF/MG), the state department of finance for Minas Gerais, Brazil, partnered with Veracode to embed security directly into its core digital infrastructure. By implementing Veracode’s comprehensive application risk management platform, SEF/MG launched a cultural shift toward DevSecOps. This collaboration enabled the government agency to significantly reduce risk, increase visibility into legacy code, and drive measurable efficiency in vulnerability remediation, ensuring a secure environment for citizen services.
About
The Secretaria de Estado de Fazenda de Minas Gerais (SEF/MG) manages the financial and tax administration for the Brazilian state of Minas Gerais. With a workforce of 3,500 employees and collaborators, SEF/MG is dedicated to providing reliable, efficient, and secure digital services to citizens. To sustain this mission, the agency is continuously modernizing its technological infrastructure, adopting robust DevSecOps practices to protect sensitive government data and ensure regulatory compliance.
The Challenge: Visibility and Late-Stage Remediation
As SEF/MG expanded its digital services and initiated the transition to DevSecOps, the IT team faced structural challenges in its application security program. The existing model lacked the necessary visibility and scalability to secure both modern applications and critical legacy systems.
Key challenges included:
- Low visibility into vulnerabilities: Development teams lacked clear, real-time insight into security flaws during the coding phase, leaving applications exposed to risk.
- Late-stage remediation: Security issues were often detected right before production deployment, causing delays, bottlenecks, and increased costs to fix flaws.
- Securing legacy code: The agency needed a scalable way to identify and address vulnerabilities deeply embedded within existing legacy systems.
- Lack of a secure development culture: SEF/MG needed to shift from a reactive to a proactive posture, requiring developers to embrace security as an integrated part of their daily workflow.
The Solution: Seamless Automation and Shift-Left Security
To build a culture of secure development, SEF/MG implemented Veracode’s platform to integrate automated security directly into its CI/CD pipelines. This approach aligned seamlessly with the agency’s goal of establishing mature DevSecOps practices without disrupting developer workflows.
The key Veracode solutions adopted included Static Analysis (SAST), Software Composition Analysis (SCA), and Veracode eLearning.
SEF/MG embedded Veracode scanning directly into its GitLab and Azure DevOps environments via API integration. By shifting security left, developers received early, actionable feedback within their Integrated Development Environments (IDEs) and automated pipelines. This proactive approach prevented vulnerabilities from progressing to the final stages of deployment. The agency also introduced Veracode eLearning to provide technical guidance, laying the groundwork for a broader cultural transformation and continuous education among its 300 developers.
The Results: Measurable Risk Reduction and Scalable Security
The partnership with Veracode delivered significant, quantifiable improvements across SEF/MG’s development operations, turning software security into an automated, efficient process.
Key outcomes include:
- Massive gains in application coverage: SEF/MG achieved 99.6% application scan coverage, scanning 283 out of 284 repositories and ensuring comprehensive visibility across its portfolio.
- Dramatically improved compliance: The agency increased its policy compliance rate from just 10.5% in April 2025 to 49.6% in February 2026, with a peak compliance rate of 73.5% during the integration phase.
- Accelerated remediation: Developers established an efficient remediation cadence, achieving an overall Mean Time to Remediate (MTTR) of ~40 days, quickly neutralizing critical risks before deployment.
- Seamless developer adoption: By automating scans via API and pipeline integrations, SEF/MG achieved a 100% developer adoption rate for automated scanning, embedding security directly into the daily workflow without friction.
- Simplified auditing and governance: Continuous visibility and technical evidence of remediation strengthened SEF/MG’s security controls, directly supporting compliance with rigorous frameworks such as ISO 27001, LGPD (GDPR), and CIS.
Conclusion
SEF/MG’s partnership with Veracode demonstrates a highly successful strategy for bringing robust application security into the public sector. By leveraging Veracode’s Application Risk Management Platform, SEF/MG shifted security left, moving from a reactive process to a proactive, automated DevSecOps workflow. This transformation drastically reduced software risk, improved compliance, and empowered developers with seamless integrations. Ultimately, Veracode provides SEF/MG with the foundation of digital trust required to deliver reliable and secure services to the citizens of Minas Gerais.