Analytics & Reporting

Using Veracode Analytics to measure, track, and communicate your security program


Veracode Analytics gives you visibility into your security program across all applications, scan types, and teams. This hub covers how to access Analytics, what dashboards are available, and how to build custom views for your specific needs.

Note: Veracode Analytics data is not real-time. Dashboards and reports refresh approximately every four hours.


Accessing Analytics

Navigate to Analytics in the top menu of the Veracode Platform.

Access requirements: Analytics access is confirmed for users with the AdministratorSecurity Lead, or Executive roles. To create or edit custom dashboards, the Analytics Creator role is also required. If you need Analytics access and don't see it in your account, contact your Administrator.


Pre-Built Dashboards

Veracode provides several pre-built dashboards you can use immediately:

Dashboard What It Shows
Security Program Overview Portfolio-wide policy compliance rate, scan coverage, and top-risk applications
Findings Status & History Open, closed, and mitigated findings over time — trend view
SCA Findings Open-source vulnerability risk and license compliance across your portfolio
Resolution & Mitigation Details Mitigation activity and remediation detail per application

Explores: Building Custom Views

Explores let you query raw Analytics data and build your own visualizations. Select from dimensions (qualitative attributes) and measures (quantitative values) to create charts, tables, and counts, then save them to dashboards.

Available Explores include:

  • Findings — Flaw data, CWEs, mitigation status, flaw age
  • IDE and Pipeline Scans — Pipeline Scan and IDE scan usage by user, language, and result
  • Users — User account data, login status, and access
  • SCA Agent-Based Scans — SCA agent scan usage and results
  • SCA Agent-Based Scan Issues — CVE and vulnerability data from SCA agent scans
  • Docs: Explore Your Data

Key Metrics to Track

Metric Why It Matters
Policy Compliance Rate The headline measure of security program health
Open Very High / High Findings Current critical risk exposure
Mean Time to Remediate (MTTR) Are teams fixing findings quickly?
New vs. Closed Findings Is the program getting ahead of or falling behind findings volume?
Scan Coverage What percentage of active applications have been scanned recently?
Fix Usage (Veracode Fix) Are developers using available tooling to speed up remediation?

Generating Reports

For sharing with stakeholders outside of Analytics:


Useful Resources


Learning Paths

Go deeper with these step-by-step learning paths on Veracode Docs:


← Back to the Getting Started Guide | ← Back to the Onboarding Hub