Fortify on Demand and SonarQube Cloud compete in the application security domain, focusing on vulnerability detection and code quality analysis. Fortify on Demand stands out with its comprehensive security scanning and robust reporting, providing a slight edge in security feature depth.
Features: Fortify on Demand delivers correlated static and dynamic results, including real-time remediation guidance. Users value its capability to integrate with various development processes and centralized testing program management. Its ability to address security across multiple scanning types is significant. SonarQube Cloud is recognized for its continuous code analysis and smooth integration with development tools. It efficiently identifies security vulnerabilities and hotspots with a balance that fits mid-sized enterprises and startups.
Room for Improvement: Fortify on Demand could improve incident management integration and reduce false positives. Enhancing configuration options and reporting flexibility with graphical improvements are also needed. Challenges include update speed for new technologies. SonarQube Cloud needs enhanced dynamic analysis and better reporting customization. The integration process for new features requires more comprehensive documentation. Reducing false positives and enriching auto-commit capabilities are also recommended.
Ease of Deployment and Customer Service: Fortify on Demand offers diverse deployment options with cloud, on-premises, and hybrid setups. Despite reliable customer service, there are inconsistencies in technical support responsiveness. SonarQube Cloud, being cloud-focused, simplifies deployment though it limits on-premises solutions. Its customer service and technical support are often praised for proactive problem-solving.
Pricing and ROI: Fortify on Demand, though expensive, provides significant value through its exhaustive feature set and security incident reduction capabilities. Its pricing supports volume-based scalability, yet some users seek more flexible structures. SonarQube Cloud's pricing, aligned with code volume, is suitable for smaller teams but can escalate for larger codebases. Users find value in its competitive pricing and all-inclusive packages despite some higher costs.
Fortify on Demand is a web application security testing tool that enables continuous monitoring. The solution is designed to help you with security testing, vulnerability management and tailored expertise, and is able to provide the support needed to easily create, supplement, and expand a software security assurance program without the need for additional infrastructure or resources.
Fortify on Demand Features
Fortify on Demand has many valuable key features. Some of the most useful ones include:
Fortify on Demand Benefits
There are several benefits to implementing Fortify on Demand. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Fortify on Demand solution.
Dionisio V., Senior System Analyst at Azurian, says, "One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that." He goes on to add, “Another reason I like Fortify on Demand is because our code often includes open source libraries, and it's important to know when the library is outdated or if it has any known vulnerabilities in it. This information is important to us when we're developing our solutions and Fortify on Demand informs us when it detects any vulnerable open source libraries.”
A Security Systems Analyst at a retailer mentions, “Being able to reduce risk overall is a very valuable feature for us.”
Jayashree A., Executive Manager at PepsiCo, comments, “Once we have our project created with our application pipeline connected to the test scanning, it only takes two minutes. The report explaining what needs to be modified related to security and vulnerabilities in our code is very helpful. We are able to do static and dynamic code scanning. When we are exploring some of the endpoints this solution identifies many loopholes that hackers could utilize for an attack. This has been very helpful and surprising how many vulnerabilities there can be.”
A Principal Solutions Architect at a security firm explains, “Its ability to perform different types of scans, keep everything in one place, and track the triage process in Fortify SSC stands out.”
PeerSpot user Mamta J., Co-Founder at TechScalable, states, "Almost all the features are good. This solution has simplified designing and architecting for our solutions. We were early adopters of microservices. Their documentation is good. You don't need to put in much effort in setting it up and learning stuff from scratch and start using it. The learning curve is not too much."
SonarQube Cloud offers static code analysis and application security testing, seamlessly integrating into CI/CD pipelines. It's a vital tool for identifying vulnerabilities and ensuring code quality before deployment.
SonarQube Cloud is widely used for its ability to integrate with tools like GitHub, Jenkins, and Bitbucket, providing critical feedback at the pull request level. It's designed to help organizations maintain clean code by acting as a quality gate. This service supports development methodologies including sprints and Kanban for ongoing vulnerability management. While appreciated for its dashboard and integration capabilities, some users find initial setup challenging and note the need for enhanced documentation. The recent addition of mono reports and microservices support offers deeper insights into security and code quality, though container testing limitations and false positives are noted drawbacks. Manual intervention is sometimes required to address detailed reporting, with external tools being necessary for comprehensive analysis. Notifications for larger teams during serious issues and streamlined integration of new features are also areas of improvement.
What are the key features of SonarQube Cloud?In specific industries, SonarQube Cloud finds application in finance and healthcare where code integrity and security are paramount. It allows teams to identify critical vulnerabilities early and ensures that software development aligns with industry regulations and standards. By continuously analyzing code, it aids organizations in deploying secure and reliable applications, fostering trust and compliance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.