# StackHawk vs Veracode

| Attribute | StackHawk | Veracode |
|---|---|---|
| **Vioscale score** | 50.5 (73% (medium)) | 58.7 (11% (low)) |
| deployment.options | `{"cloud":true}` | - |
| description.long | A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams. | Veracode provides unified application security posture management with tools for detecting, analyzing, and remediating application vulnerabilities across the software development lifecycle. |
| features.capabilities | `{"dast":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true}` | `{"sca":true,"dast":true,"sast":true,"hosting":"cloud","auto_fix_pr":true,"container_scanning":true}` |
| integrations.count | 11 | - |
| integrations.list | `[{"name":"Claude Code"},{"name":"Codex"},{"name":"Gemini CLI"},{"name":"GitHub Copilot"},{"name":"OpenCode"},{"name":"Cursor"},{"name":"Snyk"},{"name":"Auth0"},{"name":"GitHub Actions"},{"name":"GitLab"},{"name":"Jenkins"},{"name":"CircleCI"}]` | - |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | - |
| pricing | `{"type":"subscription","plans":[{"free":false,"name":"Wingman","summary":"$10/user/month","features":["Works inside Claude Code, Cursor, GitHub Copilot","Auto-configures and boots app","Runtime testing against running app","Finds and fixes vulnerabilities in same session","Auto-rescanning to verify fix","Pre-PR security attestation","Unlimited apps","50 scans/user/month"],"commitment":"monthly","components":[{"kind":"per_unit","unit":"user","amount":10,"period":"month","currency":"USD"}],"description":"For individuals and teams shipping with AI coding agents","contactSales":false,"includedLimits":{"apps":"unlimited","scans":"50/user/month"}},{"free":false,"name":"Scale","summary":"Custom pricing. Contact sales.","features":["Everything in Wingman","Attack surface discovery","Sensitive data detection","Deeper, broader scan coverage","Program reporting (coverage, fix rates by team)","Teams, roles, and enterprise support","Unlimited agentic scans"],"description":"For security teams needing attack surface discovery, coverage, and proof across every app","contactSales":true,"includedLimits":{"apps":"unlimited","scans":"unlimited"}}],"summary":"From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.","currency":"USD","freeTier":true,"sourceUrl":"https://www.stackhawk.com","retrievedAt":"2026-08-03T22:45:21.019Z","freeTrialDays":14,"startingPrice":{"amount":10,"period":"month","currency":"USD"},"billingPeriods":["month"]}` | - |
| pricing.free_tier | yes | - |
| pricing.model | freemium | commercial |
| pricing.price_level | low | - |
| pricing.transparent | no | - |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | - |
| security.soc2 | yes | - |

## Capabilities (DevSecOps Tools)

| Capability | StackHawk | Veracode |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | - | ✓ |
| DAST (dynamic analysis) | ✓ | ✓ |
| SCA / dependency scanning | - | ✓ |
| Secret scanning | - | - |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | - | - |
| **Governance** |  |  |
| OSS licence compliance | - | - |
| SBOM generation (SPDX/CycloneDX) | - | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | - | - |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud only |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | - |
| In-editor / IDE scanning | ✓ | - |
| **Licensing** |  |  |
| OSS engine available | ✓ | - |

*Source: Vioscale. Generated 2026-09-01T15:00:49.375Z. "-" = undocumented, not absent.*
