Analytics & Reporting
Using Veracode Analytics to measure, track, and communicate your security program
Veracode Analytics gives you visibility into your security program across all applications, scan types, and teams. This hub covers how to access Analytics, what dashboards are available, and how to build custom views for your specific needs.
Note: Veracode Analytics data is not real-time. Dashboards and reports refresh approximately every four hours.
Accessing Analytics
Navigate to Analytics in the top menu of the Veracode Platform.
Access requirements: Analytics access is confirmed for users with the Administrator, Security Lead, or Executive roles. To create or edit custom dashboards, the Analytics Creator role is also required. If you need Analytics access and don't see it in your account, contact your Administrator.
- Docs: Veracode Analytics
Pre-Built Dashboards
Veracode provides several pre-built dashboards you can use immediately:
| Dashboard | What It Shows |
|---|---|
| Security Program Overview | Portfolio-wide policy compliance rate, scan coverage, and top-risk applications |
| Findings Status & History | Open, closed, and mitigated findings over time — trend view |
| SCA Findings | Open-source vulnerability risk and license compliance across your portfolio |
| Resolution & Mitigation Details | Mitigation activity and remediation detail per application |
- Docs: Analytics Dashboards
Explores: Building Custom Views
Explores let you query raw Analytics data and build your own visualizations. Select from dimensions (qualitative attributes) and measures (quantitative values) to create charts, tables, and counts, then save them to dashboards.
Available Explores include:
- Findings — Flaw data, CWEs, mitigation status, flaw age
- IDE and Pipeline Scans — Pipeline Scan and IDE scan usage by user, language, and result
- Users — User account data, login status, and access
- SCA Agent-Based Scans — SCA agent scan usage and results
- SCA Agent-Based Scan Issues — CVE and vulnerability data from SCA agent scans
- Docs: Explore Your Data
Key Metrics to Track
| Metric | Why It Matters |
|---|---|
| Policy Compliance Rate | The headline measure of security program health |
| Open Very High / High Findings | Current critical risk exposure |
| Mean Time to Remediate (MTTR) | Are teams fixing findings quickly? |
| New vs. Closed Findings | Is the program getting ahead of or falling behind findings volume? |
| Scan Coverage | What percentage of active applications have been scanned recently? |
| Fix Usage (Veracode Fix) | Are developers using available tooling to speed up remediation? |
Generating Reports
For sharing with stakeholders outside of Analytics:
- Detailed Report (PDF) — Full findings for a specific application. docs.veracode.com/r/c_results_reports
- Customizable Report (PDF) — Choose which sections to include for different audiences.
- Reporting REST API — Pull data programmatically for custom dashboards or presentations. docs.veracode.com/r/Reporting_REST_API
Useful Resources
Learning Paths
Go deeper with these step-by-step learning paths on Veracode Docs:
← Back to the Getting Started Guide | ← Back to the Onboarding Hub
.png)