It enforces source-code scanning, finding vulnerabilities in source code.
Director of Information Technology at a tech consulting company with 501-1,000 employees
It enforces source-code scanning and finding vulnerabilities in source code. It would be nice if it could manage the false positives better.
Pros and Cons
- "It enforces source-code scanning, finding vulnerabilities in source code."
- "Stability could use a little improvement as we've had some issues. It runs out of memory sometimes and uses a lot of resources."
What is most valuable?
How has it helped my organization?
We're able to find vulnerabilities and weaknesses actually posting to site. We can get to these issues in our staging areas for active data and for verifying user vulnerabilities. It helps the development cycle in that we don't need other people involved in the scans. We're doing pre-scans and then getting other teams involved.
What needs improvement?
There are a lot of false positives and there's not a good way to manage them. They appear after every scan, and it would be nice to have them marked out so that we don't see them.
What was my experience with deployment of the solution?
We've had no issues with deployment.
Buyer's Guide
OpenText Core Application Security
June 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability could use a little improvement as we've had some issues. It runs out of memory sometimes and uses a lot of resources. Sometimes the scans don't work.
What do I think about the scalability of the solution?
For code scans, company size doesn't really matter so much as the size of the code. It works well with the code scans we're running. Our lines of code aren't as huge as other applications we build, and it doesn't support every type of our applications, which are primarily .NET and HPE apps.
How are customer service and support?
Technical support isn't top-notch, but it's not bad. It's just average. They take a while to resolve issues.
How was the initial setup?
The initial setup was pretty easy and straightforward.
What other advice do I have?
Find the solution that works best for your environment, using the group concept to try them all. Then determine which is best for you.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager at a tech services company with 10,001+ employees
It addresses the source code scanning and dynamic scanning in a known, correlated way.
Pros and Cons
- "I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way."
- "It could use better integration with the incident management processor."
Valuable Features
It's one of the leaders in the application security space. I've used Fortify since 2007, and I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way. I think the best way to address application security is to have multiple types of scanning and a unified view for the customer.
Improvements to My Organization
It's forced the incorporation of security in the development process. That's really the biggest benefit for us.
Room for Improvement
It could use better integration with the incident management processor. This would allow us to understand the vulnerabilities that arise in the software and how they're linked to the incident management center.
Deployment Issues
The deployment has not had issues.
Stability Issues
It is a quite stable solution.
Scalability Issues
It's quite scalable and addresses a huge volume.
Customer Service and Technical Support
It's good, but could be better to align with other main vendors, such as IBM.
Initial Setup
It's not straightforward, but it's not complex either. It could also be improved.
Other Solutions Considered
I'm very familiar with IBM and Barracuda and others. I always know HP's competition, but I feel most comfortable with HP.
Other Advice
My advice would be to look not only at the software, but also at the processor and the people who will be using the software. You should buy not just the software, but also the services to train people to use it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
OpenText Core Application Security
June 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Solution Security Architect with 1,001-5,000 employees
It has added a very quick turnaround for security code reviews, allowing us to integrate this function into the overall development and testing lifecycle.
Pros and Cons
- "Excellent – from the PoC through setup and implementation; we received timely and knowledgeable support whenever we need it."
- "It needs to support more languages."
What is most valuable?
- It's On-Demand, and cloud-based which is well suited to occasional and price-conscious use.
- Fast turn-around allows for easy integration into the development process without any major impact on development efforts.
How has it helped my organization?
It has added a very quick turnaround for security code reviews which allowed us to integrate this (formerly missing) function into the overall development and testing lifecycle.
What needs improvement?
It needs to support more languages.
For how long have I used the solution?
I've used it for three months.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Excellent – from the PoC through setup and implementation; we received timely and knowledgeable support whenever we need it.
Which solution did I use previously and why did I switch?
We tried to do it by hand (which was very time consuming and error-prone) and some tools built-in to Visual Studio (which was not widely accepted by individuals).
How was the initial setup?
We had some issue with logins and account setups, but received excellent support.
What about the implementation team?
We implemented it ourselves with the help of HP.
What was our ROI?
Don’t know since the project got cancelled.
What other advice do I have?
Take advantage of the free trial and conduct a meaningful PoC. Get a buy-in from upper management early and co-ordinate with all stakeholders (e.g. developers, testing and/or QA groups).
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
It provides an independent review of third-party applications, allowing organizations to test software before purchasing. But try the free version first as there's no "right" way to measure ROI.
Pros and Cons
- "HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software."
What is most valuable?
I was able to quickly pass compliance with HIPAA.
Correlated static and dynamic results with detailed priority guidance.
Accurate results, tailored to each application.
All results manually reviewed by application security experts .
Central testing program management for all applications.
How has it helped my organization?
HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software. Third-party vendors can upload the source code and/or provide a URL, review the results, and then publish a report back to their customer.
This service compels commercial vendors to take action to proactively fix vulnerabilities, while allowing them to remain in control of their applications. Security professionals can demand that high-priority problems be addressed and verified during the procurement or upgrade process, prior to acceptance. HP Fortify on Demand serves as an independent third-party solution to conduct unbiased analysis of applications and provide a detailed tamper-proof report back to the security team.
What needs improvement?
You are going to like the new detailed reporting. It can correlate the results from different forms of testing and prioritize them by severity to present the truest representation of application risk.
For how long have I used the solution?
1 year
What was my experience with deployment of the solution?
It was very easy to install and deploy.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No. Scalable infrastructure allows for fast turnaround times and it has no limitations based on lines of code, megabytes, or anything else.
How are customer service and technical support?
Customer Service:
Good
Technical Support:Good
Which solution did I use previously and why did I switch?
I currently use other solutions. We gave HP Fortify on Demand a try and we are very happy with the results.
How was the initial setup?
Yes. Very easy.
What about the implementation team?
We tried the free version first and then we acquired the software the product website.
What was our ROI?
Keep in mind that the calculation for return on investment and, therefore the definition, can be modified to suit the situation. It all depends on what you include as returns and costs. The definition of the term in the broadest sense just attempts to measure the profitability of an investment and, as such, there is no one "right" calculation. But, I have to say the client is very satisfied.
What's my experience with pricing, setup cost, and licensing?
Try the free version first.
Which other solutions did I evaluate?
I am already using other software. We wanted to try it and it works like a charm.
What other advice do I have?
Trust me, you want to be able to do automated and manual testing on a web application that is live.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
Checkmarx One
CrowdStrike Falcon Cloud Security
PortSwigger Burp Suite Professional
Coverity Static
Sonatype Lifecycle
GitHub Advanced Security
GitGuardian Platform
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What are the costs for Micro Focus Fortify on Demand?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?

















In terms of integration with SIM/SIEM solution, what do you use?