Getting Started Guide Hub

New to Veracode?

Start with your First 30-Day Plan

A week-by-week guide to platform setup, your first scan, and understanding your results — designed for customers to self-guide.

Go to Your First 30 Days →


Interactive Tour

See the Veracode Platform before you log in

A guided click-through tour of the platform interface, so you know where things are before your first scan. No login required.

Start the tour →

Product Quickstarts

New to a product? These step-by-step guides on Veracode Docs will get you scanning in minutes.

🔍
Static Analysis
Scan compiled code for security vulnerabilities (SAST)
View quickstart →
🕵️
SCA Agent-Based Scan
Find vulnerabilities in open-source dependencies
View quickstart →
DAST Essentials
Dynamically scan running web applications
View quickstart →
🔧
Veracode Fix
AI-suggested code fixes for your scan findings
View quickstart →
🔌
REST APIs
Automate and integrate using Veracode APIs
View quickstart →
🌎
EASM
External Attack Surface Management
View quickstart →
🧪
Security Labs
Hands-on developer security training
View quickstart →
🎓
Learning Paths
Structured learning journeys on Veracode Docs
View on Docs →

All quickstart guides open on Veracode Docs.

Guides by Role

Jump straight to the guide written for your role.

👩‍💻
Developer
IDE plugins, fix findings, Pipeline Scan
Read guide →
⚙️
DevOps Engineer
CI/CD pipelines, automation, integrations
Read guide →
👥
Team Administrator
Users, roles, teams, API credentials
Read guide →
🛡️
Security Lead
Policy, portfolio management, rollout
Read guide →
📈
Program Owner
ROI, executive reporting, leadership buy-in
Read guide →

Onboarding Topics — In Order

Work through these in sequence for the smoothest onboarding experience.

STEP 1

Platform Setup Essentials

Configure users, roles, teams, API credentials, and security policies before your first scan.

Read guide →
STEP 2

IDE Plugins & Your First Scan

Install the right IDE plugin, run your first scan, and understand what comes back.

Read guide →
STEP 3

Reading Your Scan Results

Understand severity levels, flaw categories, policy status, and what to act on first.

Read guide →
STEP 4

Remediation Planning

Turn your findings into a prioritized action plan your team can actually execute.

Read guide →
STEP 5

Integration Pathways

Connect Veracode to GitHub, Jenkins, Jira, and your existing development tools.

Read guide →
STEP 6

Scan Types & Workflows

Understand SAST, DAST, SCA, and Pipeline Scan — and which to use when.

Read guide →

Going Deeper

Advanced guides for teams ready to build a mature AppSec program.

📊 Analytics & Reporting

Measure your security program and produce reports for leadership and audits.

Read guide →

🎯 KPI Playbook

The metrics that matter for AppSec programs, with targets and reporting cadence.

Coming soon

🏷️ Custom Fields Strategy

Tag applications by team or risk tier for more meaningful analytics.

Coming soon

⌨️ Veracode CLI

Run Pipeline Scans and SCA Agent scans from your terminal or CI/CD environment.

Read guide →

📂 Application Scoping

Define your application portfolio, configure profiles, and schedule scans at scale.

Coming soon

🔍 Manual Penetration Testing

What to expect from MPT, how to prepare, and how to act on your results.

Coming soon

Further Reading

Additional guides on AppSec strategy, DevSecOps concepts, and program tools.

Still have questions?

Post in the community forums — other Veracode customers and Veracode staff check regularly and are happy to help.

Ask the Community →