We use the solution to scan our software. We scan it at every build. We run the scans and read the reports.
Independent Professional at Studio Dott. Ing. Angelo Quaglia
A fast, stable, and scalable solution that can be used to scan software
Pros and Cons
- "The solution is very fast."
- "The products must provide better integration with build tools."
What is our primary use case?
What is most valuable?
The solution is very fast.
What needs improvement?
The products must provide better integration with build tools. In SonarQube scans, the pull requests are decorated. I don't know if it is a missing integration or a limitation, but I don't see the same feature in Fortify. The developer must be able to see whether the build has failed. I would like the pull request to be decorated like SonarQube. It's just not the same experience with Fortify.
I have a problem with the Java version because our projects now use OpenJDK 7 or 17, but the scan still requires JDK 1.8. It is a problem for me, and I don't know how to change it.
For how long have I used the solution?
I have been using the solution for a couple of months.
Buyer's Guide
Fortify on Demand
January 2025
Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool is stable. I have no problem with it. I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
My team has started using it recently. I rate the tool’s scalability a nine out of ten. We don't have any issues whatsoever.
What other advice do I have?
My organization has been using the solution for at least four years. I don’t deal with technical support directly. I would recommend the solution to others. We are dealing with some issues with the report.
The reports might be meaningful, but they sometimes do not match the situation. We cannot really deal with them. We don't know if they are false positives or if they're simply not relevant because they concern vulnerabilities in the development cycle and not in the production operations. It is sort of a mystery. Overall, I rate the tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Tester at Ray Business Technologies Private Limited
An user-friendly solution for static code analysis
Pros and Cons
- "The solution is user-friendly. One feature I find very effective is the tool's automatic scanning capability. It scans replicas of the code developers write and automatically detects any vulnerabilities. The integration with CI/CD tools is also useful for plugins."
- "Fortify on Demand needs to improve its pricing."
What is our primary use case?
We use the tool for static code analysis.
What is most valuable?
The solution is user-friendly. One feature I find very effective is the tool's automatic scanning capability. It scans replicas of the code developers write and automatically detects any vulnerabilities. The integration with CI/CD tools is also useful for plugins.
The tool's AI feature analyzes security threats and recommends updating the code accordingly. One major issue that AI detected for us was logging issues and hardware vulnerabilities. Fortify On Demand identified these, allowing our developers to address and fix the issues.
What needs improvement?
Fortify on Demand needs to improve its pricing.
For how long have I used the solution?
I have been working with the product for two years.
What do I think about the stability of the solution?
I rate Fortify on Demand's stability an eight out of ten.
What do I think about the scalability of the solution?
I rate the tool's scalability an eight out of ten. My company has around 25 users.
How was the initial setup?
The initial setup experience with Fortify On Demand was straightforward for us. We installed the plugin and integrated it with our existing tools and logins. There was no need for configuration or setup—it was quite simple. The deployment time varies based on the code complexity. Once vulnerabilities are identified, the support team provides the necessary fixes.
What's my experience with pricing, setup cost, and licensing?
Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten.
What other advice do I have?
We use Burpsuite for dynamic code analysis. Fortify on Demand is a good tool for static code analysis. I rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: May 22, 2024
Flag as inappropriateBuyer's Guide
Fortify on Demand
January 2025
Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Test Lead at a financial services firm with 10,001+ employees
A highly trusted and comprehensive application security testing solution, known for its seamless integration, advanced technical capabilities, and reliability
Pros and Cons
- "What stands out to me is the user-friendliness of each feature."
- "It would be highly beneficial if Fortify on Demand incorporated runtime analysis, similar to how Contrast Security utilizes agents for proactive application security."
What is our primary use case?
We use it to scan the bank's applications systematically. This process aims to identify and address security vulnerabilities within the applications, ensuring the robustness of our security measures.
How has it helped my organization?
It stands out by generating fewer false positives which has a distinct advantage, as it translates to reduced remediation efforts, requiring less human resources and cost. The tool provides more accurate feedback to the development team, allowing them to focus their efforts on addressing genuine vulnerabilities efficiently.
What is most valuable?
I appreciate all the features, with a particular emphasis on their vulnerability scanner. For instance, in our environment where two-factor authentication is prevalent across many of our sites, the scanner efficiently identifies vulnerabilities, including those related to second-factor methods or mobile codes. What stands out to me is the user-friendliness of each feature. Given that we're a bank with multiple applications, having the flexibility to customize solutions according to the unique needs of each application is crucial.
What needs improvement?
It would be highly beneficial if Fortify on Demand incorporated runtime analysis, similar to how Contrast Security utilizes agents for proactive application security. This could enhance the solution significantly. Moreover, considering the evolving threat landscape and the inevitability of zero-day vulnerabilities, implementing mechanisms like heuristic approaches would be advantageous. By incorporating heuristic algorithms or leveraging artificial intelligence, especially in the form of behavioral analysis akin to network security practices, Fortify could evolve into a more resilient solution. This could involve heuristic analysis for source code, the introduction of AI-driven processes for enhanced security, and the identification of security hotspots.
For how long have I used the solution?
In this company, I have been using it for three months.
What do I think about the stability of the solution?
When it comes to stability, I haven't observed any issues such as crashes or performance issues during the scanning process. I would rate it ten out of ten.
What do I think about the scalability of the solution?
I would rate its scalability capabilities nine out of ten. Our approach involves a centralized team, and we conduct scans across all applications within UBS. Throughout my experience, we've successfully scanned 150 applications.
What about the implementation team?
The ability to install software often depends on individual circumstances. In my case, coming from a security background, the machines provided in our company are typically set up by the network or DevOps team.
What's my experience with pricing, setup cost, and licensing?
Despite being on the higher end in terms of cost, the biggest value lies in its abilities, including robust features, seamless integration, and high-quality findings.
Which other solutions did I evaluate?
We were considering upgrading to the enterprise level, given the need for a robust solution in the banking environment. During this evaluation, we compared Netsparker, Burp Suite, and Fortify. After conducting a proof of concept (POC) that involved testing APIs, websites, and infrastructure arrangements, we presented our analysis to management. Ultimately, Fortify was selected as the preferred choice.
What other advice do I have?
With over 12 years in application security, I've consistently observed the adoption of Fortify in major organizations like Cognizant, Barclays, and Credit Suisse. Across large banks in Europe, Fortify has established a reputation for reliability and effectiveness. Drawing on my experience, I am confident that organizations with clear problem statements and no budget constraints will find Fortify to be a comprehensive solution. Its technical capabilities and features align well with the diverse needs of large organizations in the banking sector. Overall, I would rate it ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Project Manager at Everis
Great cost benefit with good stability and reduces exposure and remediation issues
Pros and Cons
- "The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation."
- "There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes."
What is our primary use case?
We're implementing DevSecOps in Fortify only a part of the big picture. We are implementing the entire secure development lifecycle.
What is most valuable?
The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation.
What needs improvement?
There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes.
The initial setup is a bit complex.
We could have more detailed documentation. They could offer some quick start or some extra guidance regarding the implementation.
I'd like to see more interactive application security And more IDE integration and integration with VS Code and Eclipse. I would like to see more features of this kind.
For how long have I used the solution?
I've used this solution over the last 12 months at least.
What do I think about the stability of the solution?
The solution is stable. It's reliable. It doesn't crash or freeze. There aren't bugs or glitches.
What do I think about the scalability of the solution?
We haven't tried to scale the solution just yet. As we didn't take the SaaS solution, scalability may be limited for us. I'm unsure. I can't really comment on that.
Currently, we have about 20 people on the development team.
Right now, we don't plan to increase usage.
How are customer service and technical support?
The technical support is fine, however, it would be very helpful, especially during implementation, if there was more documentation and help surrounding setup.
Which solution did I use previously and why did I switch?
We did not use a different solution previously. Before we had this solution, we were just evaluating other solutions and looking at the costs, and trying to bring in something newer, like an integrated automated secure stack, or something like that.
How was the initial setup?
We found that the initial setup a bit complex. It's not exactly straightforward. For a newbie, there's a learning curve, and that can slow things down a bit.
Our deployment took about three to four months.
What about the implementation team?
We only deployed in our company and we didn't use a consultant or integrator. We handled it completely in-house.
What was our ROI?
At this time, I don't have an answer on the return of investment. As far as I can see, it's necessary. If we got exposed or had a data leak it would cost the company dearly. With that in mind, while I can see there's an ROI, I can't provide an exact number.
What's my experience with pricing, setup cost, and licensing?
We pay for licensing. We do pay an extra cost for implementing the infrastructure into the cloud.
Which other solutions did I evaluate?
I've briefly looked at Kiuwan and compared it to this solution. We also looked at Veracode.
What other advice do I have?
We're just a customer and we offer consulting services.
We are bringing up all the infrastructure inside GCP. It's not ready yet, and we're still implementing it. We're going to bring it up next week, probably, in terms of the infrastructure. We'll perform the SSC installation, install the controller and sensors.
The most important thing a company needs to do is to pay attention to the license calculation. They need to know how many licenses are going to be used. They need to understand the Micro Focus offer. That way, you won't be charged if you have surpassed the application limit. This is very important. That's something we faced in the past that caused a lot of problems. We needed to estimate the sizing correctly of the infrastructure. Doing that will bring value to the builds and deployments. Otherwise, you're going to spend a lot of time doing the scanning, and the developers will be very mad.
I'd rate the solution ten out of ten. It's the best on the market for me.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Devops Engineer at BNP Paribas
The vulnerability detection and scanning features are solid
Pros and Cons
- "The vulnerability detection and scanning are awesome features."
- "The UI could be better. Fortify should also suggest new packages in the product that can be upgraded. Currently, it shows that, but it's not visible enough. In future versions, I would like more insights about the types of vulnerabilities and the pages associated with the exact CVE."
What is our primary use case?
We are the central team that manages Fortify end-to-end and provides it as a solution to internal users. We are using SonarQube for code review, but we use Fortify and Nexus IQ for DevOps.
What is most valuable?
The vulnerability detection and scanning are awesome features.
What needs improvement?
The UI could be better. Fortify should also suggest new packages in the product that can be upgraded. Currently, it shows that, but it's not visible enough. In future versions, I would like more insights about the types of vulnerabilities and the pages associated with the exact CVE.
That will help us understand what's affecting the CVE. Initially, it's about finding the safer package version. Fortify should automatically recommend the safest version, so we can go to the vendor and request that. Once we identify the vulnerability, we can implement a remediation plan.
For how long have I used the solution?
We just started using Fortify on Demand.
What do I think about the stability of the solution?
Fortify is stable.
What do I think about the scalability of the solution?
Fortify is scalable enough. We have 10,000-plus users on it.
How are customer service and support?
Micro Focus support is slow, and they should improve that.
Which solution did I use previously and why did I switch?
We've been working with SonarQube for five years. SonarQube can show us the initial test and how your code is developed over time. It gives us insight into how a specific project is progressing. That's the great thing about SonarQube. Once the code goes into the Fortify or Nexus, it's mostly a safety check. SonarQube catches most of the vulnerabilities in Python at the development stage.
How was the initial setup?
The product itself is easy to set up, but establishing the necessary culture and structure is a bit complex. We need to develop a culture and create sub-teams within the teams. Each team needs a security coordinator who can relate what new things are coming in, such as CVEs or new scans that need to be done.
For maintenance, we have a team of two product owners who are heavily involved with the product itself. We have around three or four people with a good understanding of deploying and maintaining the solution.
What other advice do I have?
I rate Micro Focus Fortify on Demand eight out of 10. It's a great product, and I recommend it. You should deploy it as part of the TechOps implementation.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Enterprise Systems Analyst at a manufacturing company with 10,001+ employees
Scans run in the background and security analysts are available if an issue comes up
Pros and Cons
- "One of the valuable features is the ability to submit your code and have it run in the background. Then, if something comes up that is more specific, you have the security analyst who can jump in and help, if needed."
- "It's still a little bit too complex for regular developers. It takes a little bit more time than usual. I know static code scan is not the main focus of the tool, but the overall time span to scan the code, and even to set up the code scanning, is a bit overwhelming for regular developers."
- "If you have a continuous integration in place, for example, and you want it to run along with your build and you want it to be fast, you're not going to get it. It adds to your development time."
What is our primary use case?
We use it for externally exposed applications that we want to scan before releasing them to production. As you can imagine, it's important to make sure they're secure and that we will not be exposed. For internal apps, we use other static code scanning, primarily SonarQube. But Fortify on Demand is for externally exposed applications.
How has it helped my organization?
Because of the kind of products we deal with, and the kind of customers we have, we have really specific security requirements and practices we need to follow, specifically applying to our SDLC. Our SDLC dictates that we have security scanning, and that improves our code quality. Thankfully, we have never had any kind of serious security flaw or any kind of deviation of the process. We can certainly account for that because of the security tools and analysis that we have prior to moving code to production.
What is most valuable?
One of the valuable features is the ability to submit your code and have it run in the background. Then, if something comes up that is more specific, you have the security analyst who can jump in and help, if needed. I think that's really useful.
What needs improvement?
It's still a little bit too complex for regular developers. It takes a little bit more time than usual. I know static code scan is not the main focus of the tool, but the overall time span to scan the code, and even to set up the code scanning, is a bit overwhelming for regular developers. That's one of the reasons we don't use it throughout the company and for all our applications, only for the ones we judge to be most important.
Also, if you have a continuous integration in place, for example, and you want it to run along with your build and you want it to be fast, you're not going to get it. It adds to your development time.
And it's too expensive to afford to run it for every application all the time. That's certainly something that requires improvement.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
I haven't really encountered any issues with stability.
What do I think about the scalability of the solution?
No issues with scalability. It has been able to handle all our workload so far.
How are customer service and technical support?
Our experience with tech support has been good. We haven't needed support that much but whatever we needed we were able to find on their website. There were a couple of things regarding the licensing and payment that we had to get some help with. But it was quick and easy.
Which solution did I use previously and why did I switch?
We didn't have a previous solution. We researched a couple of the tools, but we ended up using Fortify because of the comprehensive scans they have, and mainly because they are focused on the kind of apps that we have and the kind of requirements we have. They are able to cover most of the standards and practices that we need to adhere to.
How was the initial setup?
The initial setup was straightforward. We had onsite training from HPE to help set up the local environment and first scans, and that was helpful.
What's my experience with pricing, setup cost, and licensing?
The subscription model, on a per-scan basis, is a bit expensive. That's another reason we are not using it for all the apps. That subscription model is probably something that needs improvement.
Which other solutions did I evaluate?
We looked at CheckMarkx and SonarQube Enterprise. As I said, we are currently using SonarQube for other apps, but we use the open-source version. We tried to use the Enterprise version but it didn't cover all the aspects that we needed it to cover.
What other advice do I have?
Understand what you want to get out of it and be sure to fully understand what you will be paying per scan if you go for the subscription model. As I said, having to scan hundreds or thousands of apps using that subscription model and doing that several times a week, or several times a day, may increase your costs. That might be something that you need to look at.
I rate it at nine out of 10. It's not a 10 because of the cost model, it's a bit pricey, and the slowness, it could be a little bit faster. I understand the reasons why but you just need to be aware before you start using it that the local scan won't be as fast as the static code scan.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Fernando VizerSenior Information Technology Architect at a computer software company with 11-50 employees
Real User
I did a scan, discovered the default only includes critical and high issues, then when I requested to include medium and low ranked issues, they ask me to pay again for a scan. It is annoying and will force me to look for a competitor. It is this way even if it is the same code I already uploaded.
Sr. Cloud Solution Architect - SAP on Azure at Accenture
Has a good user interface but code technology needs improvement
Pros and Cons
- "The user interface is good."
- "There are lots of limitations with code technology. It cannot scan .net properly either."
What is our primary use case?
We use it as the source for code review for static code analysis.
What is most valuable?
The user interface is good.
What needs improvement?
There are lots of limitations with code technology. It cannot scan .net properly either.
For how long have I used the solution?
I've been using it for the last five to six years.
How was the initial setup?
The initial setup of this solution on-premises is easy; however, we have had difficulties installing it online in our clients' environments.
What about the implementation team?
We used both in-house and vendor teams for deployment.
What other advice do I have?
On a scale from one to ten, I would rate Micro Focus Fortify on Demand at five because we get better scan results from other tools.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Solution architect at NTT
Beneficial functionality, pinpoints issues for resolution, but interface could improve
Pros and Cons
- "The most valuable feature of Micro Focus Fortify on Demand is the information it can provide. There is quite a lot of information. It can pinpoint right down to where the problem is, allowing you to know where to fix it. Overall the features are easy to use, you don't have to be a coder. You can be a manager, or in IT operations, et cetera, anyone can use it. It is quite a well-rounded functional solution."
- "Micro Focus Fortify on Demand could improve the user interface by making it more user-friendly."
What is our primary use case?
Micro Focus Fortify on Demand is used for detecting vulnerabilities in code, looking at libraries, and finding where there are vulnerabilities within unpatched code.
What is most valuable?
The most valuable feature of Micro Focus Fortify on Demand is the information it can provide. There is quite a lot of information. It can pinpoint right down to where the problem is, allowing you to know where to fix it. Overall the features are easy to use, you don't have to be a coder. You can be a manager, or in IT operations, et cetera, anyone can use it. It is quite a well-rounded functional solution.
The allocations to different members of a team are good. If you find a problem, you can delegate the task to patch the particular code.
What needs improvement?
Micro Focus Fortify on Demand could improve the user interface by making it more user-friendly.
For how long have I used the solution?
I have been using Micro Focus Fortify on Demand for approximately two years.
What do I think about the stability of the solution?
I have found Micro Focus Fortify on Demand stable.
What do I think about the scalability of the solution?
Micro Focus Fortify on Demand is a scalable solution.
We have several customers using this solution. There are approximately 1,000 developers using the solution.
How are customer service and support?
The support from Micro Focus Fortify on Demand is great. They have been very good to answer our questions. They have their own Fortify on Demand team and they will help you resolve your problems.
How was the initial setup?
The initial setup is straightforward.
The installation can take a couple of hours depending on what the deployment is, such as, on cloud or on-premise. Additionally, the size of the code that will be put on the system can impact the time, but it does not take long.
What about the implementation team?
We did the implementation ourselves. I was able to use YouTube to help me with the process, there's quite a lot of information on there with Micro Focus going through tutorials on how to use the solution.
What's my experience with pricing, setup cost, and licensing?
The pricing model it's based on how many applications you wish to scan.
Which other solutions did I evaluate?
I have evaluated other solutions, such as Contrast Security.
What other advice do I have?
I would recommend Micro Focus Fortify on Demand to others.
I rate Micro Focus Fortify on Demand a seven out of ten.
The reason why I've rated the solution a seven is because there are other solutions, such as Contrast Security which are further developing in IS, and some better technology with current scalability or in the security software area.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Veracode
Checkmarx One
Mend.io
Sonatype Lifecycle
Acunetix
GitHub Advanced Security
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
Klocwork
Tenable.io Web Application Scanning
Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What are the costs for Micro Focus Fortify on Demand?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
Hello Fernando, great to see that the Fortify solution continues to provide value by reducing risk. Great honest review.
Jason Lebrecht