name: Veracode API FinOps specification: FinOps Framework specificationVersion: '1.0' schema: https://www.finops.org/framework/ alignedWith: framework: FinOps Foundation Framework frameworkUrl: https://www.finops.org/framework/ dataSpec: FOCUS dataSpecVersion: '1.3' dataSpecUrl: https://focus.finops.org/focus-specification/v1-3/ provider: Veracode providerId: veracode publisherName: Veracode, Inc. serviceCategory: Application Security created: '2026-05-04' # Provenance stamped 2026-08-11: this artifact was written by the API Evangelist # bulk sweep dated 2026-05-04, not harvested from the provider. See roadmap#35. method: generated modified: '2026-05-05' reconciled: false tags: - Application Security - DevSecOps - FinOps - FOCUS description: 'FOCUS-aligned FinOps stub for Veracode: enterprise application-security SaaS subscription with no public pricing or usage/billing API. API access is bundled with the platform subscription.' sources: - https://www.veracode.com/pricing - https://docs.veracode.com/r/About_Veracode_API_Best_Practices notes: No public pricing. Meters are not invented; API call counts are operational telemetry rather than billable units. Reconciliation deferred pending customer-portal billing data. billingModel: pricingCategory: Subscription billingFrequency: Annual billingCurrency: USD chargeCategories: - Purchase focusColumns: ServiceName: Veracode Application Security Platform ServiceCategory: Application Security ProviderName: Veracode PublisherName: Veracode, Inc. InvoiceIssuerName: Veracode, Inc. BillingCurrency: USD meters: - name: platform_subscription description: Annual Veracode platform subscription line; entitlements for SAST / DAST / SCA scans and seats are scoped in the order form. unit: varies aggregation: sum principles: - name: Visibility description: Veracode exposes scan and finding telemetry via the Reporting, Findings, and Summary Report REST APIs; there is no public cost / usage API. Track entitlement consumption (scan-counts, seats) against the order-form scope. - name: Allocation description: Allocation is contract-level (which application portfolios and teams are entitled). Internal chargeback typically rides on application ownership tags applied in the Veracode platform. - name: Optimization description: Optimization levers include scoping which apps are scanned, scan cadence, and avoiding wasted polling (the docs require 2-minute minimum spacing on status checks and cap retries at 5). - name: Accountability description: Accountability sits with the AppSec team that owns the Veracode tenant; finance owns the annual subscription line. maintainers: - FN: Kin Lane email: kin@apievangelist.com url: https://apievangelist.com