Getting Started Guide Hub

New to Veracode?

Start with your First 30-Day Plan

A week-by-week guide to platform setup, your first scan, and understanding your results β€” designed for customers to self-guide.

Go to Your First 30 Days β†’


Product Quickstarts

New to a product? These step-by-step guides on Veracode Docs will get you scanning in minutes.

       πŸ”      
       Static Analysis      
       Scan compiled code for security vulnerabilities (SAST)      
       View quickstart β†’      
       πŸ•΅οΈ      
       SCA Agent-Based Scan      
       Find vulnerabilities in open-source dependencies      
       View quickstart β†’      
       βš‘      
       DAST Essentials      
       Dynamically scan running web applications      
       View quickstart β†’      
       πŸ”§      
       Veracode Fix      
       AI-suggested code fixes for your scan findings      
       View quickstart β†’      
       πŸ”Œ      
       REST APIs      
       Automate and integrate using Veracode APIs      
       View quickstart β†’      
       πŸŒŽ      
       EASM      
       External Attack Surface Management      
       View quickstart β†’      
       πŸ§ͺ      
       Security Labs      
       Hands-on developer security training      
       View quickstart β†’      
       πŸŽ“      
       Learning Paths      
       Structured learning journeys on Veracode Docs      
       View on Docs β†’      

All quickstart guides open on Veracode Docs.


Guides by Role

Jump straight to the guide written for your role.

       πŸ‘©β€πŸ’»      
       Developer      
       IDE plugins, fix findings, Pipeline Scan      
Read guide β†’
       βš™οΈ      
       DevOps Engineer      
       CI/CD pipelines, automation, integrations      
Read guide β†’
       πŸ‘₯      
       Team Administrator      
       Users, roles, teams, API credentials      
Read guide β†’
       πŸ›‘️      
       Security Lead      
       Policy, portfolio management, rollout      
Read guide β†’
       πŸ“ˆ      
       Program Owner      
       ROI, executive reporting, leadership buy-in      
Read guide β†’

Onboarding Topics β€” In Order

Work through these in sequence for the smoothest onboarding experience.

STEP 1

Platform Setup Essentials

Configure users, roles, teams, API credentials, and security policies before your first scan.

Read guide β†’
STEP 2

IDE Plugins & Your First Scan

Install the right IDE plugin, run your first scan, and understand what comes back.

Read guide β†’
STEP 3

Reading Your Scan Results

Understand severity levels, flaw categories, policy status, and what to act on first.

Read guide β†’
STEP 4

Remediation Planning

Turn your findings into a prioritized action plan your team can actually execute.

Read guide β†’
STEP 5

Integration Pathways

Connect Veracode to GitHub, Jenkins, Jira, and your existing development tools.

Read guide β†’
STEP 6

Scan Types & Workflows

Understand SAST, DAST, SCA, and Pipeline Scan β€” and which to use when.

Read guide β†’

Going Deeper

Advanced guides for teams ready to build a mature AppSec program.

πŸ“Š Analytics & Reporting

Measure your security program and produce reports for leadership and audits.

Read guide β†’

🎯 KPI Playbook

The metrics that matter for AppSec programs, with targets and reporting cadence.

Coming soon

🏷️ Custom Fields Strategy

Tag applications by team or risk tier for more meaningful analytics.

Coming soon

⌨️ Veracode CLI

Run Pipeline Scans and SCA Agent scans from your terminal or CI/CD environment.

Read guide β†’

πŸ“‚ Application Scoping

Define your application portfolio, configure profiles, and schedule scans at scale.

Coming soon

πŸ” Manual Penetration Testing

What to expect from MPT, how to prepare, and how to act on your results.

Coming soon

Further Reading

Additional guides on AppSec strategy, DevSecOps concepts, and program tools.



Still have questions?

Post in the community forums β€” other Veracode customers and Veracode staff check regularly and are happy to help.

Ask the Community β†’