No more typing reviews! Try our Samantha, our new voice AI agent.

OpenText Core Application Security vs Trellix IVX for Enterprise Applications comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OpenText Core Application S...
Ranking in Application Security Tools
11th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
64
Ranking in other categories
Static Application Security Testing (SAST) (9th)
Trellix IVX for Enterprise ...
Ranking in Application Security Tools
30th
Average Rating
8.0
Reviews Sentiment
5.3
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Application Security Tools category, the mindshare of OpenText Core Application Security is 3.3%, down from 4.2% compared to the previous year. The mindshare of Trellix IVX for Enterprise Applications is 0.3%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
OpenText Core Application Security3.3%
Trellix IVX for Enterprise Applications0.3%
Other96.4%
Application Security Tools
 

Featured Reviews

Himanshu_Tyagi - PeerSpot reviewer
Lead Cybersecurity at TBO
Supports secure development pipelines and improves issue detection but limits internal visibility and needs broader dashboard integration
If you have an internal team and you want your internal team to validate false positives, basically to determine whether it's a valid issue or an invalid issue, then I wouldn't recommend it much. That was the only reason we migrated from Fortify on Demand to another solution. Fortify has another tool which is Fortify WebInspect. On Demand is the outsourcing solution, and WebInspect you can use with your in-house team, which is basically the product developed by the Fortify team. For automated scanning, Fortify helps a lot. Regarding the visibility for the internal team, everyone is moving toward the DevSecOps side, and Fortify team has made good progress that you can integrate into your CICD pipeline. One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together. If you have one tool that works for different solutions, it helps a lot. They are doing good, but they should invest more on the AI side as well because AI security is evolving these days. On the cloud side, they have already made good progress, but I believe they should explore the new area related to AI security as well.
HA
General Manager at CyberTech Computer
Long-term endpoint security has protected our organization from ransomware and data loss
Trellix IVX for Enterprise Applications Collaboration is not something we are currently using. We are not using FireEye Email Security right now. We are not using the cloud version of this product. It is not difficult to manage because our team is very well trained and aware of Trellix IVX for Enterprise Applications endpoint security because we have been using it for more than 20 years. Our team is very well trained on the endpoint security. However, because we have a very distributed architecture of our organization, it is very difficult to change or replace on laptop or desktop computers. At most, only two or three engineers are involved. Trellix IVX for Enterprise Applications is very robust and easy to handle data loss protection, which are very good features. We are also using Fortinet products. The vendor team is also monitoring and does proactive measures to protect from ransomware and other security threats. We have a service level agreement with the local vendor to maintain the solution and solve other issues. The overall review rating for this product is 8 out of 10.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The SAST feature is the most valuable."
"The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic."
"Speed and efficiency are great features."
"I do not remember any issues with stability."
"The quality of application security testing reduces risk and gives very few false positives."
"The most valuable feature of Micro Focus Fortify on Demand is the information it can provide. There is quite a lot of information. It can pinpoint right down to where the problem is, allowing you to know where to fix it. Overall the features are easy to use, you don't have to be a coder. You can be a manager, or in IT operations, et cetera, anyone can use it. It is quite a well-rounded functional solution."
"The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues."
"The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives."
"Trellix IVX for Enterprise Applications is very robust and easy to handle data loss protection, which are very good features."
"Trellix IVX for Enterprise Applications positively impacts my organization by increasing security and reducing time, especially by using threat intelligence to validate signatures across all platforms, thus minimizing manual work."
"We actually saw reduced incidents with Trellix IVX for Enterprise Applications, and it has reduced the response time for us because if there is a detection of high severity, Trellix IVX for Enterprise Applications detects it quickly and we are able to respond to it promptly."
"Trellix IVX for Enterprise Applications has positively impacted my organization over the past four years, serving as one of the best security tools I have used."
 

Cons

"Takes up a lot of resources which can slow things down."
"Micro Focus Fortify on Demand could improve the user interface by making it more user-friendly."
"The UI could be better. Fortify should also suggest new packages in the product that can be upgraded. Currently, it shows that, but it's not visible enough. In future versions, I would like more insights about the types of vulnerabilities and the pages associated with the exact CVE."
"There are frequent complaints about false positives from Fortify. One day it may pass a scan with no issues, and the next day, without any code changes, it will report vulnerabilities such as password exposure."
"Primarily for a complex, advanced website, they don't really understand some of the functionalities. So for instance, they could tell us that there is a vulnerability because somebody could possibly do something, but they don't really understand the code to realize that we actually negate that vulnerability through some other mechanism in the program. In addition, the technical support is just not there. We have open tickets. They don't respond. Even if they respond, we're not seeing eye to eye. As the company got sold and bought, the support got worse."
"We typically do our bulk uploads of our scans with some automation at the end of the development cycle but the scanning can take a lot of time. If you were doing all of it at regular intervals it would still consume a lot of time. This could procedure could improve."
"The cybersecurity specialist or AppSec would need a bit of training to engage the user interface and to understand how it functions."
"There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes."
"The weak side is that it sometimes slows down the desktop computer or laptop computer."
"Customer support for Trellix IVX for Enterprise Applications is very good in theory. However, you must follow up with them for weeks and weeks for a single issue."
"Overall I find the platform useful; however, there should be ease of navigation and more actionable reporting to make investigations faster and the overall experience more efficient."
"I think Trellix IVX for Enterprise Applications can be improved by adding more involvement of artificial intelligence."
 

Pricing and Cost Advice

"The pricing model it's based on how many applications you wish to scan."
"Fortify on Demand is moderately priced, but its pricing could be more flexible."
"There are different costs for Micro Focus Fortify on Demand depending on the assessments you want to use. There is only a standard license needed to use the solution."
"It is cost-effective."
"It is not more expensive than other solutions, but the pricing is competitive."
"We used the one-time application, Security Scan Dynamic. I believe the original fee was $8,000."
"Buying a license would be feasible for regular use. For intermittent use, the cloud-based option can be used (Fortify on Demand)."
"Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten."
Information not available
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
909,153 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Construction Company
7%
Outsourcing Company
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise8
Large Enterprise46
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Micro Focus Fortify on Demand?
In comparison with other tools, they're competitive. It is not more expensive than other solutions, but their pricing is competitive. The licenses for Fortify On Demand are generally bought in unit...
What needs improvement with Micro Focus Fortify on Demand?
Areas for improvement should be contextualized post the OpenText acquisition, but back when I was working with Micro Focus, they focused heavily on enterprise-centric solutions. Now, after the acqu...
What is your primary use case for Micro Focus Fortify on Demand?
For OpenText Core Application Security, I currently support a couple of my clients who are using Fortify on Demand for their web application, CRM, and sales platform. Many good features of Fortify ...
What needs improvement with Trellix IVX for Enterprise Applications?
Endpoint services in Trellix IVX for Enterprise Applications can occasionally stop and require manual intervention. Content updates such as DAT and AMCore require troubleshooting in some environmen...
What is your primary use case for Trellix IVX for Enterprise Applications?
We have been using Trellix IVX for Enterprise Applications for one of our clients, and the console is quite intuitive. Day-to-day operations such as reviewing detection, managing endpoints, and cre...
What advice do you have for others considering Trellix IVX for Enterprise Applications?
We actually saw reduced incidents with Trellix IVX for Enterprise Applications. It has reduced the response time for us. If there is a detection of high severity, Trellix IVX for Enterprise Applica...
 

Also Known As

Micro Focus Fortify on Demand
No data available
 

Overview

 

Sample Customers

SAP, Aaron's, British Gas, FICO, Cox Automative, Callcredit Information Group, Vital and more.
Information Not Available
Find out what your peers are saying about OpenText Core Application Security vs. Trellix IVX for Enterprise Applications and other solutions. Updated: August 2026.
909,153 professionals have used our research since 2012.