

OpenText Core Application Security and Contrast Security Assess are competing in the application security domain. Based on data comparisons, Contrast Security Assess appears to have the upper hand due to its robust features.
Features: OpenText Core Application Security excels in comprehensive vulnerability detection and risk assessment, with a strong emphasis on integration capabilities. Meanwhile, Contrast Security Assess offers real-time monitoring, seamless integration within DevOps environments, and ease of use, providing a noticeable advantage in terms of features.
Room for Improvement: OpenText Core Application Security could enhance its real-time monitoring capabilities and user interface clarity while reducing false positives. It would also benefit from better integration within DevOps ecosystems. Contrast Security Assess might improve its reporting functionalities, scale-down cost-effectiveness for smaller businesses, and expand its community and marketplace support.
Ease of Deployment and Customer Service: Contrast Security Assess provides a straightforward deployment model backed by proactive customer service, ensuring efficient implementation. OpenText Core Application Security also offers an easy deployment process, focusing on robust post-deployment support to ensure users get the necessary help.
Pricing and ROI: OpenText Core Application Security captures interest with competitive pricing and the potential for quick ROI, supported by scalable cost models for varying business sizes. On the other hand, Contrast Security Assess might require a higher initial investment but offers excellent ROI through advanced automation and features, aligning cost with the value provided.
In the past, my company employed five security engineers, but with Contrast Security Assess, we only have two people.
There is definitive ROI if OpenText Core Application Security is deployed properly; it substantially reduces efforts in securing the solution while averting various application-related risks.
Contrast Security's customer support is very active and overall incredible.
I had direct interaction with them, which facilitated how we onboarded Fortify.
Support tickets often stay open for one month to three months, which leads to customer frustration.
The technical support from OpenText is very good.
Fortify is superior to many solutions because of its scalability and that it does not require massive compute capabilities for its SAST and sandboxing features.
OpenText Core Application Security is highly scalable; it is running on the cloud, and elasticity is one of the best points of a cloud environment.
If a customer wants to know the tools and the technology used for their application to scan their application, they provide less information on that.
Contrast Security Assess is genuinely more accurate than most tools I have worked with because it uses instrumentation from inside the application.
OpenText Core Application Security is stable and has minimal downtime, benefitting from AWS cloud availability.
I would love to see more customizable, out-of-the-box reporting that speaks to both technical and non-technical people without extra configuration.
One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together.
I would say OpenText Core Application Security is not very user-friendly in terms of price; it is quite high.
It would be beneficial if Fortify could check for CVEs (Common Vulnerabilities and Exposures) in third-party libraries, which I currently use a separate dependency checker tool for.
The annual licensing for Contrast Security Assess costs about $20,000 to $100,000 per year, and per application, it costs about $5,000 to $15,000 per year.
The agent lives inside the running application, allowing it to see exactly what is happening in real-time. This means we are getting accurate alerts instead of a long list of potential issues that require manual investigation.
Fortify helps me find serious issues, such as developers inadvertently leaving access tokens, including API access tokens, in the source code.
The integration of OpenText Core Application Security with existing systems for security operations benefits us by providing vulnerability management and quality gates; without both, we will always have vulnerable applications running for our customers.
Additionally, you can integrate Fortify in CICD pipeline, so you get real-time updates about the security issues in your pipeline.
| Product | Mindshare (%) |
|---|---|
| OpenText Core Application Security | 3.2% |
| Contrast Security Assess | 1.6% |
| Other | 95.2% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 8 |
| Large Enterprise | 46 |
Contrast Security Assess is an IAST platform known for accurate vulnerability detection. It integrates into development workflows, offering real-time insights into security issues with minimal false positives, supporting legacy applications and enhancing code security visibility.
Designed to integrate seamlessly into DevOps workflows, Contrast Security Assess automates real-time vulnerability detection and reduces false positives through its powerful IAST features. By continuously monitoring vulnerabilities, it provides a robust option for securing legacy applications and identifying vulnerabilities without lengthy scans. This cloud-hosted platform supports numerous programming languages, making it versatile for security testing across enterprise environments. Users benefit from detailed reports that pinpoint exact code locations requiring remediation, enhancing speed and efficiency in addressing security concerns.
What are the key features of Contrast Security Assess?Companies in industries requiring high levels of application security, such as finance and healthcare, implement Contrast Security Assess for its ability to enhance visibility and detect vulnerabilities early in the development lifecycle. Its seamless integration with DevOps processes makes it ideal for environments that prioritize agility while maintaining stringent security standards.
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.