Your First 30 Days with Veracode
A step-by-step guide for new customers
Welcome to Veracode. This guide gives you a clear, sequential path through your first 30 days — from getting access to running scans to making sense of your results. Follow the milestones below and you'll be in a strong position by the end of your first month.
Before You Start: The Big Picture
Veracode is an application security (AppSec) platform that helps you find vulnerabilities in your software before attackers do. Your goal in the first 30 days is simple: get your first scan running and understand what it found.
Week 1: Get Set Up
Your first priority is making sure your account is configured correctly and you can access the platform.
Step 1 — Confirm your account and roles
Sign in to the Veracode Platform. Your account needs specific roles to run scans and view results. The most common roles for new users are Creator, Submitter, and Reviewer. If unsure, check with your Veracode Administrator.
Step 2 — Generate API credentials
Most Veracode workflows require API credentials (an API ID and API key). Generate these from your account settings in the Veracode Platform and store them in a credentials file on your local machine.
- Docs: Generate API Credentials
Step 3 — Create an application profile
Before you can scan, you need to create an application profile. This organizes scan results and assigns policies to your application.
Step 4a — Install the IDE plugin (recommended for developers)
The fastest way to get security feedback is to scan from inside your IDE. Veracode supports VS Code, Visual Studio, JetBrains, and Eclipse — all four modern plugins support SAST, SCA, and Veracode Fix.
- Docs: IDE Plugins and Extensions
- Community: IDE Plugins & Your First Scan
Step 4b — Set up CI/CD integration (recommended for DevOps-first teams)
If your team wants to go straight to automated scanning in your pipelines rather than starting with IDE plugins, Veracode integrates directly with your SCM and CI/CD toolchain. This is a common path for teams who want pipeline-enforced security from day one.
- Docs: SCM Integrations (GitHub, GitLab, Bitbucket)
- Docs: CI/CD Build Tool Integrations (Jenkins, Azure DevOps, TeamCity, Bamboo)
- Community: Integration Pathways
Week 2: Run Your First Scan
Now you're ready to scan some code. Start with something small and manageable — don't begin with your most complex application.
Which scan type should I start with?
| Scan Type | Best For | Docs |
|---|---|---|
| IDE Scan | Fastest feedback — scan as you code | docs.veracode.com/r/IDEs |
| Pipeline Scan | Automated scanning in CI/CD pipelines | docs.veracode.com/r/Pipeline_Scan |
| CI/CD & SCM Integrations | Trigger scans automatically from GitHub, GitLab, Jenkins, Azure DevOps, and others | docs.veracode.com/r/SCM_integrations docs.veracode.com/r/c_integration_buildservs |
| Upload and Scan | Comprehensive, policy-tracked assessment | docs.veracode.com/r/Static_Analysis_Quickstart |
Pipeline Scan limits: Maximum scan time: 60 minutes · Maximum file size: 200 MB · Rate limit: 6 scans per 60 seconds per account. These limits apply to Pipeline Scan specifically. Upload and Scan has different limits — see Veracode Upload and Scan for details.
Week 3: Understand Your Results
Once your first scan completes, you'll see findings. Not every finding requires immediate action. Start by understanding the severity levels.
- Very High / High — Highest risk — prioritize these first.
- Medium — Moderate risk — plan a fix in your next sprint cycle.
- Low / Very Low — Limited risk — address opportunistically.
💡 Tip: Failing policy on your first scan is completely normal. It means you have a baseline to work from — not that something is broken.
- Docs: Review Findings
- Docs: About Security Policies
Week 4: Make a Plan
By now you have scan results and a baseline understanding of your application's security posture. Week 4 is about turning that into a plan.
- Prioritize — Fix Very High and High severity findings in your most critical applications first.
- Set up your team — Ensure the right people have the right roles and team access.
- Explore Analytics — Navigate to Analytics in the Veracode Platform to explore pre-built dashboards.
- Share results — Generate a report to share with your security or engineering leadership.
30-Day Checklist
- [ ] Account confirmed and roles assigned
- [ ] API credentials generated
- [ ] Application profile created
- [ ] IDE plugin installed
- [ ] First scan completed
- [ ] Scan results reviewed
- [ ] Policy status understood
- [ ] High/Very High severity findings identified
- [ ] Team members added with correct roles
- [ ] Analytics explored
- [ ] First report generated
Learning Paths
Go deeper with these step-by-step learning paths on Veracode Docs:
← Back to the Getting Started Guide | ← Back to the Onboarding Hub
.png)