Both editions of the product have their advantages, and they complement each other.
System Engineer at a tech services company with 501-1,000 employees
Both editions of the product have their advantages, and they complement each other.
What is most valuable?
How has it helped my organization?
Since we adopted HP Fortify, our organization has added more divisions that focus on penetration testing.
What needs improvement?
HP Fortify already covers the need for security testing and is easy to use for new users. The only thing that comes to mind regarding room for improvement are the security vulnerability updates.
For how long have I used the solution?
My company has been using this solution for about one year.
Buyer's Guide
Fortify on Demand
February 2025
Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
What was my experience with deployment of the solution?
I have not encountered any deployment, stability or scalability issues. I haven't had any complaints about technical issues from our client, either.
How are customer service and support?
I have not yet contacted customer service or technical support.
Which solution did I use previously and why did I switch?
I do know of some software that have similarities, but I’ve never used any of them before.
How was the initial setup?
Most of our clients use straightforward implementation; we recommend straightforward implementation because of the simplicity of the architecture and usage. For example, installing using the best practices for each product.
What about the implementation team?
We implemented it for our customer.
What other advice do I have?
HP Fortify is perfect for any company that creates their own applications or uses vendor-developed ones; it’s great for QA and development phases.
HP Fortify is easy to use and offers lots of integration options; those options allow us to have more diverse implementations that fit the requirements.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company distributes HP Fortify.
R&D at a tech services company with 51-200 employees
Effective on-demand feature, easy to use cloud, and great support
Pros and Cons
- "There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do."
What is our primary use case?
We are using Micro Focus Fortify on Demand because in the beginning we were using the on-premise version and it was very limited. We thought we could do everything wanted with the on-premise solution. However, it was not easy to use.
We are testing the Micro Focus Fortify on Demand solution to improve security.
We are using the on-premise version of this solution for the static code for developers. For the dynamic code, we're using Micro Focus Fortify on Demand.
What is most valuable?
There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do. We were working with a different solution called SolarCloud previously and it was limited. We are trying to find the right level of security for our needs.
For how long have I used the solution?
I have been using Micro Focus Fortify on Demand for approximately eight months.
How are customer service and support?
The support is good. Their support is in the Netherlands, sometimes it takes some time for the time zone difference between Latin America and the Netherlands but overall the support is good.
How was the initial setup?
The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic. They give you an account and that is all, you use the product.
The premise solution is more rentable. However, it is asking for a lot of effort in the implementation, administration, and integration in the pipeline. It takes time until the company comes to the right level to be able to manage this product. Even with the right partners in Latin America that work with us, it took some time.
What about the implementation team?
We had partners in Latin America that help us integrate the implementation of the Micro Focus Fortify on Demand.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive and the price could be reduced.
What other advice do I have?
My advice to others is if you choose Micro Focus Fortify on Demand, it's very simple to use. If they choose the on-premise version for the static code, they will need a person to manage it to be sure that it's integrated with all the pipelines that they developed.
I rate Micro Focus Fortify on Demand a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortify on Demand
February 2025
Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
Senior Manager at a tech services company with 10,001+ employees
It addresses the source code scanning and dynamic scanning in a known, correlated way.
Valuable Features
It's one of the leaders in the application security space. I've used Fortify since 2007, and I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way. I think the best way to address application security is to have multiple types of scanning and a unified view for the customer.
Improvements to My Organization
It's forced the incorporation of security in the development process. That's really the biggest benefit for us.
Room for Improvement
It could use better integration with the incident management processor. This would allow us to understand the vulnerabilities that arise in the software and how they're linked to the incident management center.
Deployment Issues
The deployment has not had issues.
Stability Issues
It is a quite stable solution.
Scalability Issues
It's quite scalable and addresses a huge volume.
Customer Service and Technical Support
It's good, but could be better to align with other main vendors, such as IBM.
Initial Setup
It's not straightforward, but it's not complex either. It could also be improved.
Other Solutions Considered
I'm very familiar with IBM and Barracuda and others. I always know HP's competition, but I feel most comfortable with HP.
Other Advice
My advice would be to look not only at the software, but also at the processor and the people who will be using the software. You should buy not just the software, but also the services to train people to use it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Veracode
Mend.io
Sonatype Lifecycle
Acunetix
GitHub Advanced Security
PortSwigger Burp Suite Professional
HCL AppScan
Qualys Web Application Scanning
Klocwork
Tenable.io Web Application Scanning
Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What are the costs for Micro Focus Fortify on Demand?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
In terms of integration with SIM/SIEM solution, what do you use?