Veracode Marketplace 2026: Curated AppSec Integrations for the AI Era
News | 04.08.2026
Application security teams face a growing challenge: AI-generated code, agentic development environments, and expanding attack surfaces demand deeper contextual analysis than traditional static scanners can provide. Enterprises need a trusted way to extend their existing AppSec platform with specialized capabilities without adding procurement friction or fragmented workflows.
A single, curated destination to discover, evaluate, and deploy elite security integrations on top of Veracode.
What was announced
On July 30, 2026, Veracode announced the launch of the Veracode Marketplace, a curated ecosystem that provides customers with a single, trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. The marketplace debuts with DryRun Security as its inaugural partner, delivering AI-native contextual analysis and verification to Veracode customers on day one.
Every partner is vetted for technical depth, product quality, and workflow fit. Integrations are anchored to Veracode findings for a unified audit trail, and every purchase runs through a single procurement path on a single contract with a personalized support experience. Additional partners are scheduled to join throughout 2026.
Application security has entered a new era, and no single vendor will solve it alone. Customers tell us they want the depth and rigor of the Veracode platform, combined with the freedom to choose specialized capabilities that fit their tech stack
Why this matters
For CIOs, CISOs, IT directors, and procurement leaders, the Veracode Marketplace addresses three critical pressures: the need to secure AI-generated code, the demand for verified risk prioritization over noisy findings, and the operational cost of managing multiple security vendors. By consolidating validated integrations under a single contract anchored to Veracode findings, enterprises reduce procurement overhead and gain a unified audit trail across their AppSec program.
The inaugural partnership with DryRun Security is significant: DryRun already powers more than 500,000 code reviews per month and provides native integrations with modern AI coding tools including Claude Code, Cursor, Codex, GitHub, and GitLab. Combining Veracode's deterministic scanning with DryRun's AI-reasoning delivers unified, end-to-end coverage from detection to validated remediation.
Technical details
- Curated ecosystem: vetted third-party integrations extending the Veracode platform.
- Inaugural partner: DryRun Security, with AI-native Contextual Security Analysis engine.
- Coverage expansion: intent-based and logic vulnerabilities missed by traditional static scanners.
- Native integrations: Claude Code, Cursor, Codex, GitHub, GitLab, plus repository-wide DeepScans.
- Scale: DryRun powers over 500,000 code reviews per month.
- Procurement: single contract, unified audit trail, personalized support.
- Availability: live today for Veracode customers, with additional partners in 2026.
Application security teams are not asking for more findings — they are asking for better verification of which risks actually matter
Softprom and Veracode
Softprom is the official distributor of Veracode. Enterprise teams looking to adopt the Veracode Marketplace, integrate DryRun Security, or expand their AppSec program can request a consultation and demo through Softprom's certified specialists.
Request a demo of the Veracode Marketplace and DryRun Security integration through Veracode at Softprom.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.