We use the solution for fast code review. It is integrated into our DevOps pipeline.
I find the configuration of rules in Fortify Application Defender useful. Its integration is also easy.
The product should integrate industry-standard code review tools internally with its system. This would streamline the coding process, as developers wouldn't need multiple tools for code review and security checks. Many independent and open-source tools are available, from Apache to various libraries. Using multiple DevOps pipeline tools can slow the turnaround time.
I have been working with the product for three months.
I rate the tool's stability an eight out of ten.
I rate the tool's scalability a seven out of ten. However, I'm concerned about how it handles an increasing number of lines of code. As the complexity grows, so does the time it takes for the tool to review everything. I want more clarity on how Fortify Application Defender handles multiple threats.
We have numerous endpoints, but the tool runs in our pipeline, meaning it operates in the cloud. All our code is configured there, and the tool runs integration testing, unit testing, user testing, and final production code tests.
It's a day-to-day experience. It's utilized almost every day as part of our pipeline runs. Each team responsible for integration testing, human testing, user access testing, and preproduction testing runs it whenever they take a build.
I used Checkmarx before Fortify Application Defender. Checkmarkx's pricing model, licensing, and renewal were confusing. Hence, we switched to Fortify Application Defender. Its implementation, support, and cost influenced our decision.
I rate the tool's deployment a six out of ten. The initial setup was more complex because it lacked a standard integration method. The tool's initial setup took one week, and the pipeline setup took another week. I deployed two people from my DevOps team for the setup. However, there's no need for any additional personnel for maintenance. It runs in the pipeline without requiring any ongoing maintenance unless there are changes to the rules.
I rate the solution's pricing a five out of ten. It comes as an annual cloud subscription. The tool's pricing is around 50 lakhs.
I rate the overall solution a seven out of ten. If cost is a factor, I'd recommend considering this solution. However, for extreme quality, Checkmarx might be a preferable choice.