Friday, July 31, 2026

Veracode Launches “Veracode Marketplace” to Accelerate Application Security Integrations in the AI Development Era

Related stories

Leading application risk management solutions provider, Veracode, has unveiled Veracode Marketplace, a dedicated online ecosystem that will enable organizations to discover, assess, and adopt application security tools from third party providers. The launch is significant in that it signals a move towards openness and multi-vendor application security management with AI native code analysis solutions provider, DryRun Security, as Veracode’s first ever technology partner.

With contemporary software development being increasingly characterized by agentic coding environments and rapid artificial intelligence adoption, security professionals have been faced with the task of retaining the structural approach to enterprise security solutions while at the same time incorporating specialized tools for assessment of business logic. This challenge has been met through Veracode Marketplace which is essentially a single destination for enterprise ready pre-integration of Veracode’s security platform.

Redefining Enterprise AppSec Procurement and Integration

For avoiding integration sprawl and procurement hassles, the Veracode Marketplace requires very high operational standards from all its software vendors that work through it. There is detailed vetting of all its partners for their technical prowess.

Key infrastructure benefits of the marketplace include:

  • Unified Security Context: The integrations of third parties allow for results to be directly linked to the data model from Veracode, ensuring a continuous audit trail throughout the Software Development Lifecycle (SDLC).
  • Simplified Purchase: Enterprises have the ability to review and procure certified integrations through a single contract channel without dealing with complicated onboarding of vendors and separate billing.
  • Unified Enterprise Support: Users receive integrated support across their platform and partners’ integrations.

“Application security has entered a new era, and no single vendor will solve it alone,” said Ajay Nigam, Chief Product Officer at Veracode. “Customers tell us they want the depth and rigor of the Veracode platform, combined with the freedom to choose specialized capabilities that fit their tech stack. The Veracode Marketplace is our answer. Our vision is a curated ecosystem where the best security innovators build on top of Veracode, so customers can adopt what they need in days. DryRun Security is exactly the kind of partner that makes this vision a reality.”

Also Read: Emergent Reaches Unicorn Status Within 12 Months of Launch, Secures $130 Million Series C at $1.5 Billion Valuation

DryRun Security Joining as Inaugural Launch Partner

DryRun Security joins the market as the founder with an AI-native contextual security engine tailored for today’s development environment. In contrast to traditional static analysis security testing (SAST) solutions which only use syntax-based rules, DryRun Security takes into account developer intent, application behavior, and exploitability of the code.

The solution enables a deeper code scanning coverage for detecting business logic vulnerabilities that are missed by other solutions. The DryRun Security solution works natively in developers’ tools such as Claude Code, Cursor, Codex, GitHub, and GitLab and scans over 500,000 codes per month via DeepScans and natural language policy controls.

Combining Veracode’s deterministic scanning with the AI reasoning of DryRun allows covering the whole process from vulnerability detection to remediation.

“Application security teams are not asking for more findings they are asking for better verification of which risks actually matter,” said James Wickett, CEO and Co-Founder of DryRun Security. “We built DryRun to reason across intent, behavior, and application context the dimensions of risk that cannot always be captured in a predefined rule. Through the Veracode Marketplace, enterprises can bring that capability into the security programs and development workflows they already use.”

“What makes this partnership powerful is the context layer,” Nigam closed. “AI-led reasoning can surface vulnerabilities, but the quality of that reasoning is only as good as the underlying contextual understanding with which it’s working. Veracode‘s platform brings rich, multi-dimensional context built from years of security intelligence, cross-language findings, and deep code insight. DryRun’s multi-model reasoning engine builds deep contextual understanding directly from the code. This partnership adds Veracode’s security intelligence as a complementary source of evidence, extending coverage and enriching results for shared customers. Together, the platforms give developers and AI coding agents more information to understand, prioritize, and remediate risk with confidence. That’s the benefit of leveraging two best-in-class tools together.”

Subscribe

- Never miss a story with notifications


    Latest stories