We have an application sending service that we are providing to our customers and we are using Micro Focus Fortify on Demand to ensure our applications are secure.
GM - Technology at a outsourcing company with 10,001+ employees
Effective security analysis, stable, but occasional false positives
Pros and Cons
- "The most valuable features are the server, scanning, and it has helped identify issues with the security analysis."
- "The most valuable features are the server, scanning, and it has helped identify issues with the security analysis."
- "We typically do our bulk uploads of our scans with some automation at the end of the development cycle but the scanning can take a lot of time. If you were doing all of it at regular intervals it would still consume a lot of time. This could procedure could improve."
- "We typically do our bulk uploads of our scans with some automation at the end of the development cycle but the scanning can take a lot of time."
What is our primary use case?
What is most valuable?
The most valuable features are the server, scanning, and it has helped identify issues with the security analysis.
What needs improvement?
We typically do our bulk uploads of our scans with some automation at the end of the development cycle but the scanning can take a lot of time. If you were doing all of it at regular intervals it would still consume a lot of time. This could procedure could improve.
We are receiving false positives. We then have to repeat the scan even though it is a false positive and tell it to ignore some of those issues. Some of the false positives could be a design issue which we will know, but they keep coming up on the report.
I have found the processes a bit cumbersome for the developers.
For how long have I used the solution?
I have been using this solution for approximately eight years.
Buyer's Guide
OpenText Core Application Security
April 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
What do I think about the stability of the solution?
I did not have any problems with the stability of this solution.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and support?
We did have some issues but we did not contact the technical support of Micro Focus.
How was the initial setup?
The initial setup was a medium effort, not too complex. However, the bulk scan uploads took time. Overall it took an average amount of time and it was easy to integrate and work with.
What's my experience with pricing, setup cost, and licensing?
The solution is a little expensive.
What other advice do I have?
I rate Micro Focus Fortify on Demand a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager at Everis
Great cost benefit with good stability and reduces exposure and remediation issues
Pros and Cons
- "The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation."
- "The solution saves us a lot of money, and we're trying to reduce exposure and costs related to remediation."
- "There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes."
- "There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes."
What is our primary use case?
We're implementing DevSecOps in Fortify only a part of the big picture. We are implementing the entire secure development lifecycle.
What is most valuable?
The solution saves us a lot of money. We're trying to reduce exposure and costs related to remediation.
What needs improvement?
There's a bit of a learning curve. Our development team is struggling with following the rules and following the new processes.
The initial setup is a bit complex.
We could have more detailed documentation. They could offer some quick start or some extra guidance regarding the implementation.
I'd like to see more interactive application security And more IDE integration and integration with VS Code and Eclipse. I would like to see more features of this kind.
For how long have I used the solution?
I've used this solution over the last 12 months at least.
What do I think about the stability of the solution?
The solution is stable. It's reliable. It doesn't crash or freeze. There aren't bugs or glitches.
What do I think about the scalability of the solution?
We haven't tried to scale the solution just yet. As we didn't take the SaaS solution, scalability may be limited for us. I'm unsure. I can't really comment on that.
Currently, we have about 20 people on the development team.
Right now, we don't plan to increase usage.
How are customer service and technical support?
The technical support is fine, however, it would be very helpful, especially during implementation, if there was more documentation and help surrounding setup.
Which solution did I use previously and why did I switch?
We did not use a different solution previously. Before we had this solution, we were just evaluating other solutions and looking at the costs, and trying to bring in something newer, like an integrated automated secure stack, or something like that.
How was the initial setup?
We found that the initial setup a bit complex. It's not exactly straightforward. For a newbie, there's a learning curve, and that can slow things down a bit.
Our deployment took about three to four months.
What about the implementation team?
We only deployed in our company and we didn't use a consultant or integrator. We handled it completely in-house.
What was our ROI?
At this time, I don't have an answer on the return of investment. As far as I can see, it's necessary. If we got exposed or had a data leak it would cost the company dearly. With that in mind, while I can see there's an ROI, I can't provide an exact number.
What's my experience with pricing, setup cost, and licensing?
We pay for licensing. We do pay an extra cost for implementing the infrastructure into the cloud.
Which other solutions did I evaluate?
I've briefly looked at Kiuwan and compared it to this solution. We also looked at Veracode.
What other advice do I have?
We're just a customer and we offer consulting services.
We are bringing up all the infrastructure inside GCP. It's not ready yet, and we're still implementing it. We're going to bring it up next week, probably, in terms of the infrastructure. We'll perform the SSC installation, install the controller and sensors.
The most important thing a company needs to do is to pay attention to the license calculation. They need to know how many licenses are going to be used. They need to understand the Micro Focus offer. That way, you won't be charged if you have surpassed the application limit. This is very important. That's something we faced in the past that caused a lot of problems. We needed to estimate the sizing correctly of the infrastructure. Doing that will bring value to the builds and deployments. Otherwise, you're going to spend a lot of time doing the scanning, and the developers will be very mad.
I'd rate the solution ten out of ten. It's the best on the market for me.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
OpenText Core Application Security
April 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
Senior System Analyst at Azurian
Makes it easy to discover hidden vulnerabilities in our open source libraries
Pros and Cons
- "One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that."
- "Fortify on Demand has helped us more easily ensure the security of our client's application, which works with sensitive information such as payments and taxation."
- "During development, when our developer makes changes to their code, they typically use GitHub or GitLab to track those changes. However, proper integration between Fortify on Demand and GitHub and GitLab is not there yet. Improved integration would be very valuable to us."
- "When we sent a question about the product to their support team, we had to wait a while but they did send us a response eventually."
What is our primary use case?
We create technology solutions for clients and on one project we were requested to use Fortify on Demand after the client had read a good report about it. They sent us the report and recommended its use.
In this case, we were using Java to program the client's solution and so we used Fortify on Demand alongside our Java development operations, for the purpose of improving the application's security.
The work we were doing for the client involved creating a billing system that they would use to manage payments and taxes for other companies in Chile. We've only used Fortify on Demand for this one client so far.
Because Fortify on Demand was so new to us, we decided to go with the trial version first and figure out the costing at a later stage.
How has it helped my organization?
Fortify on Demand has helped us more easily ensure the security of our client's application, which works with sensitive information such as payments and taxation. Without it, we would have to spend much more time finding hidden weaknesses in our code.
What is most valuable?
One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that.
Another reason I like Fortify on Demand is because our code often includes open source libraries, and it's important to know when the library is outdated or if it has any known vulnerabilities in it. This information is important to us when we're developing our solutions and Fortify on Demand informs us when it detects any vulnerable open source libraries.
What needs improvement?
During development, when our developer makes changes to their code, they typically use GitHub or GitLab to track those changes. However, proper integration between Fortify on Demand and GitHub and GitLab is not there yet. Improved integration would be very valuable to us.
Similarly, I would love to see some kind of tracing solution for use in stress testing. So when we stress the application on a certain page or on a certain platform, we would be able to see a complete stress test report which could quickly tell us about weak points or failures in the application.
Further potential for improvement is that, when we deploy our Java WAR files for review in the QA area, we want to be able to create a report in Fortify on Demand right from within this deployment stage. So it might inspect or check the solution's Java WAR package directly and come up with a report in this crucial phase of QA.
For how long have I used the solution?
I have been using Fortify on Demand for about a month or so.
What do I think about the stability of the solution?
Overall, we have not had any issues with stability, although we have not used it for very long.
What do I think about the scalability of the solution?
We have had no problems with scalability in our current use case, which is only one client at the moment. As a cloud service, it has satisfied our requirements well and we haven't had any situations where scalability is an issue.
How are customer service and technical support?
When we sent a question about the product to their support team, we had to wait a while but they did send us a response eventually. I think that they could work on reacting faster to support questions.
Which solution did I use previously and why did I switch?
We have also tried SonarQube, but Fortify on Demand appealed to us more due to their source code review with emphasis on open source vulnerabilities. Fortify seems stronger in that aspect and we like to use many open source libraries in our work.
How was the initial setup?
The setup is easy and it only takes about 30 minutes to perform a basic code review in Java when dealing with WAR files.
It can get more complicated when you want to fine-tune the reporting interface to give only the details that you want to see. This is because the initial configuration depends on other variables like the scope of the review, the client's preferences, the technician's preferences, and other factors.
When it comes to launching Fortify on Demand and connecting it to our codebase, it's quite easy. Getting quick reviews done on WAR files is a relatively simple procedure.
What about the implementation team?
Our company implements Fortify on Demand ourselves on behalf of our client. When the client requests any changes, we then implement it for them.
What's my experience with pricing, setup cost, and licensing?
We are still using the trial version at this point but I can already see from the trial version alone that it is a good product. For others, I would say that Fortify on Demand might look expensive at the beginning, but it is very powerful and so you shouldn't be put off by the price.
In our case, we are constrained by the client's budget, but others might find that the price is not too bad. It all depends on the budget.
What other advice do I have?
For us, Fortify on Demand is a good quality product that I can recommend for a few reasons, including:
- Very useful source code review and vulnerability detection.
- Clear and easy-to-read test results and reports.
- Good integration with other platforms during development.
I would rate Fortify on Demand a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Systems Analyst at a retailer with 5,001-10,000 employees
An extremely scalable, flexible, and stable solution that reduces the overall risk and gives us assurance
Pros and Cons
- "Being able to reduce risk overall is a very valuable feature for us."
- "Secure code is an important part of our day-to-day development activities, so having code out there gives us some reasonable assurance that it is not vulnerable or open to attack, and it certainly makes our overall risk posture better."
- "They have a release coming out, which is full of new features. Based on their roadmap, there's nothing that I would suggest for them to put in it that they haven't already suggested. However, I am a customer, so I always think the pricing is something that could be improved. I am working with them on that, and they're very flexible. They work with their customers and kind of tailor the product to the customer's needs. So far, I am very happy with what they're able to provide. Their subscriptions could use a little bit of a reworking, but that would be about it."
- "However, I am a customer, so I always think the pricing is something that could be improved."
What is our primary use case?
All in-house developed code or a third-party developed code on our behalf is scanned via Fortify on Demand. Any results for unsecure code, vulnerabilities, or issues are passed back to the development teams for remediation.
How has it helped my organization?
Secure code is an important part of our day-to-day development activities. So, having code out there gives us some reasonable assurance that it is not vulnerable or open to attack. It certainly makes our overall risk posture better.
What is most valuable?
Being able to reduce risk overall is a very valuable feature for us.
What needs improvement?
They have a release coming out, which is full of new features. Based on their roadmap, there's nothing that I would suggest for them to put in it that they haven't already suggested. However, I am a customer, so I always think the pricing is something that could be improved. I am working with them on that, and they're very flexible. They work with their customers and kind of tailor the product to the customer's needs. So far, I am very happy with what they're able to provide. Their subscriptions could use a little bit of a reworking, but that would be about it.
What do I think about the stability of the solution?
It is a very stable product. They are constantly updating and keeping it up to date. There are no issues.
What do I think about the scalability of the solution?
It is extremely scalable and flexible. We scan very small applications from our in-house innovations team and all the way up to millions of lines of code from our e-commerce teams. We currently have about 50 users, but the number varies. Some development teams are fairly small, and some are fairly large.
How are customer service and technical support?
Technical support is very good. I've never had an issue that we couldn't resolve. If we have a scan running and we need it to finish sooner, they will allocate extra resources to it if we identify. We've had very good results with their tech support.
Which solution did I use previously and why did I switch?
This is the first solution that was implemented. I inherited this from somebody else. We are a government organization, so we have to do an RFP next year to renew. We'll see how it goes.
How was the initial setup?
The basic scanning is not very complex. When you get into more detailed scanning such as APIs, the level of complexity is moderate. However, when you are scanning that type of application, you usually have teams available that know what to do and what the configuration needs to be. We did our first scan within two days.
What about the implementation team?
It was implemented in-house. We have in-house expertise. Our strategy was basically just to stand it up and use the default settings initially with a pilot. We planned to do some pilot scans and get a good feel for the product, and then adjust accordingly on an ongoing basis.
I managed it for two years single-handedly. As we expand and add more and more applications, we are adding extra hands. If we're looking at an FTE, equivalency is probably 0.5 to 0.75 people to manage it.
What was our ROI?
Looking for a return on investment on security is a little challenging. Some CIOs might argue one way or another. Some look at it as a cost, and some look at it as cost avoidance. I'm a security professional, and I look at it as cost avoidance. So, we're avoiding breaches, people being able to manipulate the code or cause any issues, and downtime. I always look at the positives of the product. If we eliminate any of the security risks or attack factors on these products before they go live, we're doing due diligence in making sure that the product stays up and running, especially for something like e-commerce.
What's my experience with pricing, setup cost, and licensing?
Their subscriptions could use a little bit of a reworking, but I am very happy with what they're able to provide.
What other advice do I have?
We plan to keep using this solution. Every year, we seem to have more and more code, and they add more and more features such as third-party library assessments, etc. Open source has become a big thing as companies try and save money, but with open source comes additional risk. This solution helps us mitigate the risk of those open-source components. So, we're using this more and more as we move forward.
The important part of this is automation. There are lots of automation options for this tool. Initially, trying to do it manually was a great start, but we kind of got lost a little bit along the way of implementing it. We should have done more automation right from the beginning, made it our standard, and created the policies. Sometimes, you put the cart before the horse. The tool does a great job, and you get lost in the results. It does provide good results and good information, but I think it's very important to have those policies and procedures in place right up front with this product. It will save you a lot of time in the end.
The biggest lesson that I have learned from using this product is that even if you have the best people, there are always vulnerabilities and things that will surprise you.
I would rate Micro Focus Fortify on Demand a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Officer at Location world
Has good price and support and works very well for web applications
Pros and Cons
- "We have the option to test applications with or without credentials."
- "They have very good support, but there is always room for improvement."
What is our primary use case?
We use this solution for our web applications.
What is most valuable?
We have the option to scan web applications on demand. We have the option to do dynamic analysis. We also have an on-premise solution for static code analysis.
We have the option to test applications with or without credentials.
What needs improvement?
Overall, it's very good. They have very good support, but there is always room for improvement.
For how long have I used the solution?
I've been using this solution for two to three years.
How are customer service and support?
They are helpful, and we have a good relationship with them. I'd rate them an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It was straightforward. It took us two or three months because we had to integrate with our DevOps and pipeline solutions. It took a bit of extra time.
In terms of maintenance, we need to update the version. Micro Focus releases new versions every two months or so.
What about the implementation team?
We had our DevOps manager, and then we had two people from IT. We also had the support of the provider. We also worked with a partner to help us to implement faster.
What's my experience with pricing, setup cost, and licensing?
I'd rate it an eight out of ten in terms of pricing.
What other advice do I have?
Overall, I'd rate it a nine out of ten. We are very satisfied with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a computer software company with 51-200 employees
User-friendly, stable, and scalable
Pros and Cons
- "The solution is user-friendly."
- "I would like the solution to add AI support."
What is our primary use case?
The solution is used for web application listing, like, SaaS.
What is most valuable?
The solution is user-friendly.
What needs improvement?
I would like the solution to add AI support.
For how long have I used the solution?
I have been using the solution for one month.
What do I think about the stability of the solution?
I give the stability a nine out of ten.
What do I think about the scalability of the solution?
I give the scalability a nine out of ten.
We have three people using the solution in our organization.
How are customer service and support?
I am satisfied with the technical support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used SonarQube which is an open-source solution. We switched because we needed an easy-to-understand and configure UI.
How was the initial setup?
I give the initial setup a nine out of ten. The deployment took a few hours and required one person to implement.
What other advice do I have?
I give the solution a nine out of ten.
I recommend the solution to others and I am totally satisfied with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Advisor Solution Architect at a tech services company with 10,001+ employees
Moderately priced solution with fantastic stability
Pros and Cons
- "Fortify on Demand's best feature is that there's no need to install and configure it locally since it's on the cloud."
- "Fortify on Demand's stability is fantastic - I've never seen slowness, and it performs consistently."
- "An improvement would be the ability to get vulnerabilities flowing automatically into another system."
- "An improvement would be the ability to get vulnerabilities flowing automatically into another system."
What is our primary use case?
I mainly use Fortify on Demand for static scanning.
What is most valuable?
Fortify on Demand's best feature is that there's no need to install and configure it locally since it's on the cloud.
What needs improvement?
An improvement would be the ability to get vulnerabilities flowing automatically into another system.
For how long have I used the solution?
I've been using Fortify on Demand for over a year.
What do I think about the stability of the solution?
Fortify on Demand's stability is fantastic - I've never seen slowness, and it performs consistently.
Which solution did I use previously and why did I switch?
I previously used ShiftLeft, but Fortify on Demand gives me a portal, and it's much easier to get details about the issues affecting us.
How was the initial setup?
The initial setup is very simple because no installation is necessary - you just need to access the application and configure it.
What about the implementation team?
We used a vendor team.
What's my experience with pricing, setup cost, and licensing?
Fortify on Demand is moderately priced, but its pricing could be more flexible.
What other advice do I have?
I would rate Fortify on Demand nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Project Manager at LINS
Affordable and scalable solution
Pros and Cons
- "Fortify on Demand can be scaled very easily."
- "Fortify on Demand is affordable, and its licensing comes with a year of support."
- "Fortify on Demand could be improved with support in Russia."
- "Fortify on Demand could be improved with support in Russia."
What is our primary use case?
Fortify on Demand is primarily used in DevSecOps in a banking environment.
What needs improvement?
Fortify on Demand could be improved with support in Russia.
For how long have I used the solution?
I've been working with Fortify on Demand for two years.
What do I think about the stability of the solution?
Fortify on Demand is stable.
What do I think about the scalability of the solution?
Fortify on Demand can be scaled very easily.
How was the initial setup?
Deployment takes between four to six months.
What about the implementation team?
We use an in-house team.
What's my experience with pricing, setup cost, and licensing?
Fortify on Demand is affordable, and its licensing comes with a year of support.
What other advice do I have?
I would give Fortify on Demand a rating of nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. We are official security partners of Micro Focus.
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Popular Comparisons
Checkmarx One
Coverity Static
PortSwigger Burp Suite Professional
Sonatype Lifecycle
GitHub Advanced Security
GitGuardian Platform
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What are the costs for Micro Focus Fortify on Demand?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?


















Hello Fernando, great to see that the Fortify solution continues to provide value by reducing risk. Great honest review.
Jason Lebrecht