Try our new research platform with insights from 80,000+ expert users
S S RAMA KRISHNA MURTHY  SURI - PeerSpot reviewer
Senior Manager at valuelabs LLP
MSP
Jul 6, 2022
It supports most languages and integrates well with other solutions
Pros and Cons
  • "Fortify supports most languages. Other tools are limited to Java and other typical languages. IBM's solutions aren't flexible enough to support any language. Fortify also integrates with lots of tools because it has API support."
  • "We have some stability issues, but they are minimal."

What is our primary use case?

Fortify is used for static scans — cold-scanning.

What is most valuable?

Fortify supports most languages. Other tools are limited to Java and other typical languages. IBM's solutions aren't flexible enough to support any language. Fortify also integrates with lots of tools because it has API support.

What needs improvement?

We have some stability issues, but they are minimal.

For how long have I used the solution?

We've been using Fortify for two or three years

Buyer's Guide
OpenText Core Application Security
March 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

Fortify is stable. 

What do I think about the scalability of the solution?

Fortify is scalable. 

How are customer service and support?

Whenever we have any issues, Micro Focus support has been helpful. They have lots of products, and they're established in the market. When you open a ticket, you get an immediate response by phone.

How was the initial setup?

The initial setup is straightforward and the second or third-tier support is available whenever we face an issue or something. Most of the components are plug-and-play, so it doesn't take much time. 

What other advice do I have?

I rate Micro Focus Fortify on Demand. This is a good solution for doing static analysis. There is also a dynamic component, but we haven't used it because we are unsure how flexible it is. We are using it only for static scanning.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1250178 - PeerSpot reviewer
Security Information Manager at a tech services company with 10,001+ employees
Real User
Feb 1, 2022
Solid usability for security and vulnerability issues
Pros and Cons
  • "The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues."
  • "In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise. In the next release, we need more reports and more analytic views for all the applications. There is no enterprise view in Fortify. I would like enterprise views and reports."

What is our primary use case?

I use it for SAST, security analysis static code.

What is most valuable?

The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues.

What needs improvement?

In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise.

In the next release, we need more reports and more analytic views for all the  applications. There is no enterprise view in Fortify. I would like enterprise views and reports.

For how long have I used the solution?

I am using Micro Focus Fortify on Demand for one year.

What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

It is scalable. Micro Focus Fortify on Demand requires a big hardware with a big processing capacity, but it is scalable.

How are customer service and support?

Their customer support is very good. I sometimes need it, and I get the answer quickly. They are very helpful.

How was the initial setup?

The initial setup is not so easy, but not so difficult. I would say it is medium difficulty.

What other advice do I have?

On a scale of one to ten, I would give Micro Focus Fortify on Demand an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
OpenText Core Application Security
March 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,873 professionals have used our research since 2012.
reviewer961944 - PeerSpot reviewer
R&D at a tech services company with 51-200 employees
Real User
Jan 8, 2022
Effective on-demand feature, easy to use cloud, and great support
Pros and Cons
  • "There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do."

    What is our primary use case?

    We are using Micro Focus Fortify on Demand because in the beginning we were using the on-premise version and it was very limited. We thought we could do everything wanted with the on-premise solution. However, it was not easy to use. 

    We are testing the Micro Focus Fortify on Demand solution to improve security.

    We are using the on-premise version of this solution for the static code for developers. For the dynamic code, we're using Micro Focus Fortify on Demand.

    What is most valuable?

    There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do. We were working with a different solution called SolarCloud previously and it was limited. We are trying to find the right level of security for our needs.

    For how long have I used the solution?

    I have been using Micro Focus Fortify on Demand for approximately eight months.

    How are customer service and support?

    The support is good. Their support is in the Netherlands, sometimes it takes some time for the time zone difference between Latin America and the Netherlands but overall the support is good.

    How was the initial setup?

    The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic. They give you an account and that is all, you use the product.

    The premise solution is more rentable. However, it is asking for a lot of effort in the implementation, administration, and integration in the pipeline. It takes time until the company comes to the right level to be able to manage this product. Even with the right partners in Latin America that work with us, it took some time.

    What about the implementation team?

    We had partners in Latin America that help us integrate the implementation of the Micro Focus Fortify on Demand.

    What's my experience with pricing, setup cost, and licensing?

    The solution is expensive and the price could be reduced.

    What other advice do I have?

    My advice to others is if you choose Micro Focus Fortify on Demand, it's very simple to use. If they choose the on-premise version for the static code, they will need a person to manage it to be sure that it's integrated with all the pipelines that they developed. 

    I rate Micro Focus Fortify on Demand a seven out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Information Security Engineer at a comms service provider with 501-1,000 employees
    Real User
    May 11, 2021
    Provides a lower number of false positives and is reliable and easy to use
    Pros and Cons
    • "The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives."
    • "Integration to CI/CD pipelines could be improved. The reporting format could be more user friendly so that it is easy to read."

    What is our primary use case?

    We use it for normal, daily source code reviews and code analysis.

    What is most valuable?

    The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives.

    It is easy to install, and the cost is fair.

    What needs improvement?

    I would like to see easier integration to CI/CD pipelines. The reporting format could be more user friendly so that it is easy to read.

    For how long have I used the solution?

    I've been working with Micro Focus Fortify on Demand for three years.

    What do I think about the stability of the solution?

    There were some issues with it before, but I think they have been fixed now.

    What do I think about the scalability of the solution?

    There were several limitations when I was using it before, but I am sure that they have been fixed by now.

    How are customer service and technical support?

    My experience with technical support has been very good.

    How was the initial setup?

    The initial setup is straightforward and not that complex. We had some support from IT.

    What's my experience with pricing, setup cost, and licensing?

    The price is fair compared to that of other solutions.

    What other advice do I have?

    If you are looking for commercial tools, Micro Focus Fortify on Demand is one of the best tools. It has all the features compared to those of its competitors. It is also within budget, if you're really focusing on security.

    I would rate it at eight on a scale from one to ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Project Manager at Everis
    Real User
    Jan 29, 2021
    Great cost benefit with good stability and reduces exposure and remediation issues
    Pros and Cons
    • "The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation."
    • "There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes."

    What is our primary use case?

    We're implementing DevSecOps in Fortify only a part of the big picture. We are implementing the entire secure development lifecycle.

    What is most valuable?

    The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation.

    What needs improvement?

    There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes.

    The initial setup is a bit complex.

    We could have more detailed documentation. They could offer some quick start or some extra guidance regarding the implementation.

    I'd like to see more interactive application security And more IDE integration and integration with VS Code and Eclipse. I would like to see more features of this kind.

    For how long have I used the solution?

    I've used this solution over the last 12 months at least.

    What do I think about the stability of the solution?

    The solution is stable. It's reliable. It doesn't crash or freeze. There aren't bugs or glitches.

    What do I think about the scalability of the solution?

    We haven't tried to scale the solution just yet. As we didn't take the SaaS solution, scalability may be limited for us. I'm unsure. I can't really comment on that.

    Currently, we have about 20 people on the development team.

    Right now, we don't plan to increase usage.

    How are customer service and technical support?

    The technical support is fine, however, it would be very helpful, especially during implementation, if there was more documentation and help surrounding setup.

    Which solution did I use previously and why did I switch?

    We did not use a different solution previously. Before we had this solution, we were just evaluating other solutions and looking at the costs, and trying to bring in something newer, like an integrated automated secure stack, or something like that.

    How was the initial setup?

    We found that the initial setup a bit complex. It's not exactly straightforward. For a newbie, there's a learning curve, and that can slow things down a bit.

    Our deployment took about three to four months.

    What about the implementation team?

    We only deployed in our company and we didn't use a consultant or integrator. We handled it completely in-house.

    What was our ROI?

    At this time, I don't have an answer on the return of investment. As far as I can see, it's necessary. If we got exposed or had a data leak it would cost the company dearly. With that in mind, while I can see there's an ROI, I can't provide an exact number.

    What's my experience with pricing, setup cost, and licensing?

    We pay for licensing. We do pay an extra cost for implementing the infrastructure into the cloud. 

    Which other solutions did I evaluate?

    I've briefly looked at Kiuwan and compared it to this solution. We also looked at Veracode.

    What other advice do I have?

    We're just a customer and we offer consulting services.

    We are bringing up all the infrastructure inside GCP. It's not ready yet, and we're still implementing it. We're going to bring it up next week, probably, in terms of the infrastructure. We'll perform the SSC installation, install the controller and sensors.

    The most important thing a company needs to do is to pay attention to the license calculation. They need to know how many licenses are going to be used. They need to understand the Micro Focus offer. That way, you won't be charged if you have surpassed the application limit. This is very important. That's something we faced in the past that caused a lot of problems. We needed to estimate the sizing correctly of the infrastructure. Doing that will bring value to the builds and deployments. Otherwise, you're going to spend a lot of time doing the scanning, and the developers will be very mad.

    I'd rate the solution ten out of ten. It's the best on the market for me.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Jason Lebrecht US - PeerSpot reviewer
    Jason Lebrecht USSr. Manager 5G & MEC (Edge) Strategy at a tech services company with 10,001+ employees
    Top 20Real User

    Hello Fernando, great to see that the Fortify solution continues to provide value by reducing risk. Great honest review.



    Jason Lebrecht

    reviewer1361028 - PeerSpot reviewer
    Information Security Manager at a tech services company with 501-1,000 employees
    Real User
    Dec 1, 2020
    Easy to set up, stable and scalable
    Pros and Cons
    • "It's a stable and scalable solution."
    • "Reporting could be improved."

    What is our primary use case?

    We use Micro Focus Fortify on Demand to access web applications and more.

    What needs improvement?

    Reporting could be improved. It would nice to export to an Excel sheet or another spreadsheet. At the moment, my only option is a PDF.

    Micro Focus Fortify on Demand is tailored towards more web application APIs, and I would like to see mobile applications added to the next release.

    For how long have I used the solution?

    We've been using Micro Focus Fortify on Demand for almost two years.

    What do I think about the stability of the solution?

    Focus Fortify on Demand is a stable solution.

    What do I think about the scalability of the solution?

    Focus Fortify on Demand is a scalable solution. 

    How was the initial setup?

    The setup and installation were straightforward. 

    What other advice do I have?

    On a scale from one to ten, I'll give it an eight.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user1345719 - PeerSpot reviewer
    Project Analyst at a financial services firm with 1,001-5,000 employees
    Real User
    Oct 31, 2020
    A cost-effective and intuitive solution for checking vulnerabilities during the development process
    Pros and Cons
    • "The most valuable feature is the capacity to be able to check vulnerabilities during the development process. The development team can check whether the code they are using is vulnerable to some type of attack or there is some type of vulnerability so that they can mitigate it. It helps us in achieving a more secure approach towards internal applications. It is an intuitive solution. It gives all the information that a developer needs to remediate a vulnerability in the coding process. It also gives you some examples of how to remediate a vulnerability in different programming languages. This solution is pretty much what we were searching for."
    • "It natively supports only a few languages. They can include support for more native languages. The response time from the support team can also be improved. They can maybe include video tutorials explaining the remediation process. The remediation process is sometimes not that clear. It would be helpful to have videos. Sometimes, the solution that the tool gives in the GUI is not straightforward to understand for the developer. At present, for any such issues, you have to create a ticket for the support team and request help from the support team."

    What is our primary use case?

    We use it for statistical analysis for Java applications that are used in the collection process of a bank. It is also used for an internal web page. The tellers use this web page in the branches to make money transactions, such as withdrawals, deposits, etc.

    What is most valuable?

    The most valuable feature is the capacity to be able to check vulnerabilities during the development process. The development team can check whether the code they are using is vulnerable to some type of attack or there is some type of vulnerability so that they can mitigate it. It helps us in achieving a more secure approach towards internal applications.

    It is an intuitive solution. It gives all the information that a developer needs to remediate a vulnerability in the coding process. It also gives you some examples of how to remediate a vulnerability in different programming languages. This solution is pretty much what we were searching for.

    What needs improvement?

    It natively supports only a few languages. They can include support for more native languages. The response time from the support team can also be improved. 

    They can maybe include video tutorials explaining the remediation process. The remediation process is sometimes not that clear. It would be helpful to have videos. Sometimes, the solution that the tool gives in the GUI is not straightforward to understand for the developer. At present, for any such issues, you have to create a ticket for the support team and request help from the support team.

    For how long have I used the solution?

    I have been using this solution for two or three months.

    What do I think about the stability of the solution?

    It has been pretty stable.

    What do I think about the scalability of the solution?

    It is scalable, but we haven't scaled it much. Currently, we have ten users, but it is capable of taking many more users.

    How are customer service and technical support?

    Their support is good, but sometimes, they take a bit longer. For high severity incidents, they should properly identify the team that has to be engaged to solve an issue. I would rate them an eight out of ten.

    How was the initial setup?

    The initial setup was pretty much straightforward. It was quite easy to implement. 

    It is quite intuitive, and the training model that they have helps the development team in using it easily. The deployment process took only about two weeks.

    In terms of the implementation strategy, it started with a kickoff meeting with the provider who offered the solution. We involved the development team, security information team, and infrastructure team from the beginning. They all knew what can be done with the solution and what role they are going to play in the implementation process, which helped a lot to achieve a pretty short implementation time.

    What's my experience with pricing, setup cost, and licensing?

    It is cost-effective.

    What other advice do I have?

    It is a great solution. It is cost-effective for a secure development process. If an enterprise wants to adopt the DevOps process, Micro Focus Fortify on Demand is a great starting point. 

    I would rate Micro Focus Fortify on Demand a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Co-Founder at TechScalable
    Real User
    Oct 13, 2020
    A feature-rich solution for simplified designing and architecting
    Pros and Cons
    • "Almost all the features are good. This solution has simplified designing and architecting for our solutions. We were early adopters of microservices. Their documentation is good. You don't need to put in much effort in setting it up and learning stuff from scratch and start using it. The learning curve is not too much."
    • "In terms of communication, they can integrate a few more third-party tools. It would be great if we can have more options for microservice communication. They can also improve the securability a bit more because security is one of the biggest aspects these days when you are using the cloud. Some more security features would be really helpful."

    What is our primary use case?

    We are architecting applications for e-commerce websites similar to Amazon. Everything is running on the cloud, and Micro Focus Fortify on Demand is totally integrated with our solution at this point in time.

    What is most valuable?

    Almost all the features are good. This solution has simplified designing and architecting for our solutions. We were early adopters of microservices.

    Their documentation is good. You don't need to put in much effort in setting it up and learning stuff from scratch and start using it. The learning curve is not too much.

    What needs improvement?

    In terms of communication, they can integrate a few more third-party tools. It would be great if we can have more options for microservice communication.

    They can also improve the securability a bit more because security is one of the biggest aspects these days when you are using the cloud. Some more security features would be really helpful.

    For how long have I used the solution?

    I have been using this solution for three years.

    What do I think about the stability of the solution?

    We have not come across anything major. We have been using it for quite a while, and we are happy with it. 

    What do I think about the scalability of the solution?

    Scalability is good. Our customer bases are not that huge. Bigger enterprises may have trouble in scaling it, but for our load of work, it is working fine.

    We have more than ten users. We are a very small startup, and we don't have too many people. 

    How are customer service and technical support?

    Till now, we have not raised any tickets. If we are stuck with something, we just google and find out. We use their documentation, which is good enough. That's why we didn't raise any technical queries or things like that.

    How was the initial setup?

    It was good. I don't think we struggled that much.

    What about the implementation team?

    We implemented it ourselves. We have two people to maintain this solution.

    Which other solutions did I evaluate?

    We didn't evaluate any other solution. I was trying to find out which solution should I use, and I just saw good reviews of this solution. This was the first solution that we tried out, and we liked it. We started with a trial, and it was doing good. Our necessities were met, so we didn't try to figure out any other competitive tool in the market. 

    What other advice do I have?

    You can choose this product for sure with a lot of confidence. It entirely depends on how you are exploring the stuff and trying to integrate it. Designing has to be good. It has all the features, but exploring the features and using it as per your need is important. It is not that features are not there. You just need to explore them and know how to use them. 

    I would rate Micro Focus Fortify on Demand an eight out of ten. It is a good product. However, it needs improvements from the security aspect and from the aspect of integrations with other popular tools in the market.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.