Fortify on Demand and Checkmarx One compete in the application security space. Fortify on Demand seems to have an upper hand in expert guidance and real-time visibility, while Checkmarx One excels in supporting various languages and integrations.
Features: Fortify on Demand offers compliance support, manual review of results, and correlated scanning for multiple scan types with expert guidance. It provides a client portal for real-time project visibility along with 24/7 technical assistance. Checkmarx One features comprehensive scanning across numerous languages without needing code compilation and supports incremental scanning. It also provides automation options and integrates with third-party tools.
Room for Improvement: Fortify on Demand could enhance user-friendly report generation, add more language support, and reduce false positives. There is also scope for better dynamic scanning time, visual reporting, and integration with bug tracking systems. Checkmarx One needs to improve on handling false positives, ease of integration with CI/CD systems, and dynamic application security testing, along with enhanced reporting capabilities.
Ease of Deployment and Customer Service: Fortify on Demand supports on-premises, public cloud, and hybrid deployment. Users have mixed experiences with customer service, noting both responsiveness and a need for improvement in some transitions. Checkmarx One is deployable across private, public, and hybrid clouds but faces challenges in technical support responsiveness for complex issues.
Pricing and ROI: Fortify on Demand is considered expensive, with its pricing model potentially unsuitable for all users due to licensing and integration fees, though it effectively enhances security. Checkmarx One also has a notable cost, especially for smaller setups, but its comprehensive security approach is seen as justifying the investment through prevention of security breaches.
Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
Fortify on Demand is a web application security testing tool that enables continuous monitoring. The solution is designed to help you with security testing, vulnerability management and tailored expertise, and is able to provide the support needed to easily create, supplement, and expand a software security assurance program without the need for additional infrastructure or resources.
Fortify on Demand Features
Fortify on Demand has many valuable key features. Some of the most useful ones include:
Fortify on Demand Benefits
There are several benefits to implementing Fortify on Demand. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Fortify on Demand solution.
Dionisio V., Senior System Analyst at Azurian, says, "One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that." He goes on to add, “Another reason I like Fortify on Demand is because our code often includes open source libraries, and it's important to know when the library is outdated or if it has any known vulnerabilities in it. This information is important to us when we're developing our solutions and Fortify on Demand informs us when it detects any vulnerable open source libraries.”
A Security Systems Analyst at a retailer mentions, “Being able to reduce risk overall is a very valuable feature for us.”
Jayashree A., Executive Manager at PepsiCo, comments, “Once we have our project created with our application pipeline connected to the test scanning, it only takes two minutes. The report explaining what needs to be modified related to security and vulnerabilities in our code is very helpful. We are able to do static and dynamic code scanning. When we are exploring some of the endpoints this solution identifies many loopholes that hackers could utilize for an attack. This has been very helpful and surprising how many vulnerabilities there can be.”
A Principal Solutions Architect at a security firm explains, “Its ability to perform different types of scans, keep everything in one place, and track the triage process in Fortify SSC stands out.”
PeerSpot user Mamta J., Co-Founder at TechScalable, states, "Almost all the features are good. This solution has simplified designing and architecting for our solutions. We were early adopters of microservices. Their documentation is good. You don't need to put in much effort in setting it up and learning stuff from scratch and start using it. The learning curve is not too much."
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.