Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Sr. Manager 5G & MEC (Edge) Strategy at a tech services company with 10,001+ employees
Real User
Top 20
Aug 25, 2017
We can load the details and within a few days, receive the results of intrusion attacks, although it needs to have better packaged reporting capabilities.
Pros and Cons
  • "I don’t know of any other On-Demand enterprise solution like this one where we can load the details and within a few days, receive the results of intrusion attacks, and work with HP Security Experts when needed for clarification"
  • "With Rapid7 I utilized its reporting capabilities to deliver Client Reports within just a few minutes of checking the data. I believe that HP’s FoD Clients could sell more services to clients if HP put more effort into delivering visually pleasing reporting capabilities."

How has it helped my organization?

The HP FoD effort allowed my client to utilize this service anytime their internal IT team was overwhelmed with workloads. FoD gives them an option to utilize the additional HP Services when they are overwhelmed with other IT Security needs across the company.

What is most valuable?

  • The ability to utilize the Client Portal, which provided my clients with a view of the project status, vulnerabilities and needed remediation steps in real-time
  • I don’t know of any other On-Demand enterprise solution like this one where we can load the details and within a few days, receive the results of intrusion attacks, and work with HP Security Experts when needed for clarification
  • The process was easy to follow and we were supported by 24/7 by TAM personnel to help with any fire drills. This was helpful many times when I needed a quick answer late at night or early in the morning

What needs improvement?

  • I believe that sales packages should be posted for single applications, and packages of multiple applications. For example, we have one-time a package for single applications, and 12 month unlimited use for static and a package for static & dynamic testing. It would be nice to see packages posted for a single application, and groups of three, five, or 10 applications. More than 10 applications would need to be custom pricing like you have today.
  • I would like it to be easier to understand, and have better packaged reporting capabilities. For most of the reporting I needed, I exported to Excel and then had to produce more visually accepted reports for Executive Clients. With Rapid7 I utilized its reporting capabilities to deliver Client Reports within just a few minutes of checking the data. I believe that HP’s FoD Clients could sell more services to clients if HP put more effort into delivering visually pleasing reporting capabilities.

What do I think about the stability of the solution?

Because the product is based on HP’s Fortify Platform, the product is great.

Buyer's Guide
OpenText Core Application Security
December 2025
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I can’t answer this question appropriately yet as I only utilized the service for one application so far.

How are customer service and support?

Customer Service:

10/10 - Christine Bobba, Gerald and the whole TAM Team were very supportive. Stuart Ward does a great job running his TAM Team focused on customer service.

Technical Support:

Jason Powell was really support from a technical perspective. He was able to quickly gather the details we needed to resolve security issues with the code or set up.

Which solution did I use previously and why did I switch?

I’ve used Rapid7 and Qualys Security Solutions in Managed Service Environments for previous clients. Both are really good solutions, but I’ve not utilized any other On-Demand Solution.

I switched because my client uses HP as its core product set. I needed to use Fortify and the FoD Solution allowed me to be up and running within a few short days.

How was the initial setup?

Super easy deployment and usage of the scanning capabilities. The setup was straightforward, and the ability to enter data and start the correct scan was intuitive.

What was our ROI?

We did not charge for the product, we charged for our PMO Services to run the product.

What's my experience with pricing, setup cost, and licensing?

We used the one-time application, Security Scan Dynamic. I believe the original fee was $8,000.

I would suggest, and I have, that companies should utilize the 12 month unlimited test package.

Which other solutions did I evaluate?

I searched online and FoD allowed me the best opportunity for success due to my client’s timeline.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user897402 - PeerSpot reviewer
it_user897402Works at a comms service provider with 10,001+ employees
Real User

Thanks

it_user692322 - PeerSpot reviewer
Digital Security Integration Lead at a non-tech company with 10,001+ employees
Real User
Jun 28, 2017
The quality of application security testing reduces risk and gives very few false positives.
Pros and Cons
  • "The quality of application security testing reduces risk and gives very few false positives."
  • "New technologies and DevOps could be improved. Fortify on Demand can be slow (slower than other vendors) to support new technologies or new software versions."

How has it helped my organization?

The security of our consumer-facing web sites is better.

What is most valuable?

The quality of application security testing reduces risk and gives very few false positives.

What needs improvement?

New technologies and DevOps could be improved. Fortify on Demand can be slow (slower than other vendors) to support new technologies or new software versions. DevOps requires very fast turnaround and I’m not sure HPE Fortify on Demand can do that, although they have a new product in beta for that.

What do I think about the stability of the solution?

We did not have stability issues.

What do I think about the scalability of the solution?

We did not have scalability issues.

How are customer service and technical support?

Technical support is very good.

Which solution did I use previously and why did I switch?

We didn’t have a previous solution.

How was the initial setup?

Setup was not complex, although given our size it was a challenge.

What's my experience with pricing, setup cost, and licensing?

Drive a hard bargain.

Which other solutions did I evaluate?

We evaluated IBM and Veracode.

What other advice do I have?

Go with the SaaS product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user712167 - PeerSpot reviewer
it_user712167General Manager - Application Security at a tech consulting company with 51-200 employees
Real User

Yes, It does have less positives. After being a premium customer and having taken the annual / 3 yr subscription option, we can opt for + (plus) services by which we can have a manual AUDIT to manually review our code for the 1st time. This helps reduce most of the false positives and developers and team in-charges can concentrate on actual issues / vulnerabilities or the weaknesses in existing application which is assessed. - Manoj Purandare, India

Buyer's Guide
OpenText Core Application Security
December 2025
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
it_user506661 - PeerSpot reviewer
Senior Lead at a computer software company with 1,001-5,000 employees
Real User
May 10, 2017
Helps us identify security vulnerability earlier in the development.
Pros and Cons
  • "We identified a lot of security vulnerability much earlier in the development and could fix this well before the product was rolled out to a huge number of clients."
  • "The Visual Studio plugin seems to hang when a scan is run on big projects. I would expect some improvements there."

How has it helped my organization?

Security of our applications is a huge concern for everyone now. Using quality products like HPE’s Fortify helped us minimize issues raised by the clients. Therefore, customer satisfaction in terms of the security was high.

What is most valuable?

We identified a lot of security vulnerability much earlier in the development and could fix this well before the product was rolled out to a huge number of clients.

What needs improvement?

The Visual Studio plugin seems to hang when a scan is run on big projects. I would expect some improvements there. Also, the comments added on each issue were getting lost on multiple iterations of scans, which could be fixed.

How are customer service and technical support?

Technical support is very good. We had a few issues in the initial setup and the HPE team’s support was commendable.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

Initial setup was complex; we ran into lot of memory issues. The Visual Studio plugin was not responsive, either.

What about the implementation team?

An in-house team implemented it. Don’t use the Visual Studio plugin, unless your solution is really small. Otherwise, use the command line setup.

Which other solutions did I evaluate?

It’s a tool used at the enterprise level; hence, I did not have a chance to explore other options.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user512112 - PeerSpot reviewer
Technical Lead at a tech services company with 10,001+ employees
Real User
May 10, 2017
Our client uses the audit workbench for on-the-fly defect auditing. .NET code scanning is still dependent on building the code base before running any scan.
Pros and Cons
  • "Audit workbench: for on-the-fly defect auditing."
  • ".NET code scanning is still dependent on building the code base before running any scan. Also, it's dependent on an IDE such as Visual Studio."

How has it helped my organization?

Security defects are captured early in the lifecycle and fixed quicker. Usage of Fortify has made developers more aware about security vulnerabilities and their consequences, as well as various secure programming practices.

What is most valuable?

  • Scan wizard: for configuring large scans
  • Audit workbench: for on-the-fly defect auditing
  • CLI: to integrate the tool into CI/CD

What needs improvement?

.NET code scanning is still dependent on building the code base before running any scan. Also, it's dependent on an IDE such as Visual Studio.

More conventional reporting formats need to be provided.

Also, a provision should be available to generate customized reports.

What do I think about the stability of the solution?

For code bases heavy on JavaScript, the static scan takes a long time (as long as two days). Even then, the scan crashes at times. Increasing system memory doesn't seem to improve the situation (tried with 16/32 GB system memory).

It requires a high-end system with 8/16/32 GB RAM for stable performance.

How are customer service and technical support?

I haven't reached out to HP Support so far.

Which solution did I use previously and why did I switch?

I did not previously use any product for static application security.

How was the initial setup?

Initial setup is quite easy.

What's my experience with pricing, setup cost, and licensing?

Buying a license would be feasible for regular use. For intermittent use, the cloud-based option can be used (Fortify on Demand).

Which other solutions did I evaluate?

Before choosing this product, we evaluated Veracode and Checkmarx (among licensed), and FindBugs and Yasca (among free).

What other advice do I have?

If you are already using HPE tools and services such as ALM, then Fortify is a good option, as it provides out-of-the-box support for these. Scanning capability-wise, the tool is decent enough, and is also easy to use. However, it generates a large number of false positives after a scan, which can be tedious to verify manually.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user488193 - PeerSpot reviewer
System Engineer at a tech services company with 501-1,000 employees
Consultant
Aug 31, 2016
Both editions of the product have their advantages, and they complement each other.

What is most valuable?

Both editions of the product have their advantages, and they complement each other.

How has it helped my organization?

Since we adopted HP Fortify, our organization has added more divisions that focus on penetration testing.

What needs improvement?

HP Fortify already covers the need for security testing and is easy to use for new users. The only thing that comes to mind regarding room for improvement are the security vulnerability updates.

For how long have I used the solution?

My company has been using this solution for about one year.

What was my experience with deployment of the solution?

I have not encountered any deployment, stability or scalability issues. I haven't had any complaints about technical issues from our client, either.

How are customer service and technical support?

I have not yet contacted customer service or technical support.

Which solution did I use previously and why did I switch?

I do know of some software that have similarities, but I’ve never used any of them before.

How was the initial setup?

Most of our clients use straightforward implementation; we recommend straightforward implementation because of the simplicity of the architecture and usage. For example, installing using the best practices for each product.

What about the implementation team?

We implemented it for our customer.

What other advice do I have?

HP Fortify is perfect for any company that creates their own applications or uses vendor-developed ones; it’s great for QA and development phases.

HP Fortify is easy to use and offers lots of integration options; those options allow us to have more diverse implementations that fit the requirements.

Disclosure: My company has a business relationship with this vendor other than being a customer. My company distributes HP Fortify.
PeerSpot user
it_user488208 - PeerSpot reviewer
Specialist Master/Manager at a consultancy with 10,001+ employees
Real User
Aug 31, 2016
We use it to evaluate code from a security perspective as opposed to a developer’s perspective.

Valuable Features

The static code analyzer provides views from a security perspective and it is easy to use compared to others.

Improvements to My Organization

We use it to evaluate security from the code and provide results from a security perspective as opposed to a developer’s perspective.

Room for Improvement

Reports can be better visually with graphics such as charts included. Charts (pie, bar, some graph) could show the percentage of the vulnerability categories identified, as opposed to listing them all in a table. At a higher level, it would be nice to aggregate the analysis.

Use of Solution

I have used it for 3.5 years.

Deployment Issues

I did not encounter any deployment issues. It was fairly simple and easy to install/deploy.

Customer Service and Technical Support

Technical support is 6/10. I find the Internet to be more helpful at times than their own tech support in finding answers.

Initial Setup

Initial setup was easy and intuitive: just specify the license path and install the product.

Implementation Team

We implemented it in-house.

ROI

Quality vs quantity: You pay more for a higher-quality product and meets your needs, compared to others that might be cheaper, but you have to crawl to get what you are looking for.

Other Solutions Considered

While I did evaluate others, it depends on the budget.

Other Advice

It is a good product to choose for SCA and cloud deployment. If you choose SSC, don’t always look at the price, as the other products might not conduct the same analysis as HP Fortify does. Not all products are created equal.

Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a vendor partner.
PeerSpot user
Elina Petrovna - PeerSpot reviewer
Elina PetrovnaProfessor at a government with 51-200 employees
Real User

The weakest component of Fortify is SSC. Very difficult to customize, huge infrastructure to implement and maintain and costly

it_user455427 - PeerSpot reviewer
Development and Database Manager at a financial services firm with 501-1,000 employees
Vendor
Jun 5, 2016
It works to identify security flaws that any of our applications might have.

What is most valuable?

The solution simply identifies any security flaws that any of our applications might have.

How has it helped my organization?

This identification provides us an advantage in that the service itself works to stay abreast and knowledgeable about emerging threats. Rather than have a security team dedicated to that effort, we don’t have to deal with that in a time consuming, direct manner. We don't need to have these skills in-house.

What needs improvement?

I find that while it does find a lot of legitimate threats, it tends to have a lot of false positives, and there are more false positives than I would like to see. It flags threats that sometimes are not, and when we have to investigate that it takes time. If they could improve the intelligence then I think it could really help the system function more efficiently. The dynamic time scan takes about seven days, and this could be a bit quicker. We like to incorporate the scan into every build cycle and if we have to wait for a seven day business cycle it has to go into our scheduling. If that could be improved there would be a lot of happy people.

For how long have I used the solution?

It predates my employment; I’m certain we signed up in 2013 – roughly three years ago.

What was my experience with deployment of the solution?

We have had no issues with the deployment.

What do I think about the stability of the solution?

I would say it’s fairly stable. It’s a web application so of course there are browser hiccups but I would give it a high score for stability. Once in a while there is a page refresh, but nothing major.

What do I think about the scalability of the solution?

We have four applications and we’ve been able to get them all in there, I don’t see it having a limit.

How are customer service and technical support?

Customer Service:

Customer service has been good once we get attention, which comes back to the false positive issue.

Technical Support:

Sometimes the results need clarifications. They could be a bit more responsive as once we get someone the interactions have been good and helpful.

Which solution did I use previously and why did I switch?

This was our first foray into a hosted service.

How was the initial setup?

The deployment was super easy as the interface is straightforward. It was almost too easy.

What other advice do I have?

If you haven’t run any formal scan be prepared for it to come back and be a bit scary.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Omar Sánchez (Mr.Tech) - PeerSpot reviewer
Omar Sánchez (Mr.Tech)Information Security Advisor, CISO & CIO, Docutek Services at a tech consulting company with 51-200 employees
Top 20LeaderboardConsultant

Support is offered through phone and a password-protected web portal, and also through email. In addition, the standard price allows for quarterly updates for the latest security tests for code review. Phone support is available 6 a.m. to 6 p.m. Pacific Standard Time.

it_user441546 - PeerSpot reviewer
Information Security Lead Consultant & Application Security Specialist at a energy/utilities company with 1,001-5,000 employees
Vendor
May 15, 2016
It's reduced operational costs as we minimized security incidents and ensured all vulnerabilities are remediated during the development lifecycle.

What is most valuable?

It's saved us a lot of time as we focus primarily on security consultancy work rather than tool operational work.

Also, the features SAST, DAST, Dashboard/Reports, Fortify on Demand Portal and Vulnerability Tracking, have all helped with our work.

Finally, it's reduced operational costs as we minimized security incidents and ensured all vulnerabilities are remediated during the development lifecycle.

How has it helped my organization?

The results it provides are more than 95% accurate, helping us to focus on the right things first.

Our new software procurement process benefited as well as we use this as a central control to provide security assurance and evaluate the quality of our deliverables.

Its ease-of-use has influenced developer behavior and enabled them to follow security principles.

What needs improvement?

It would be useful if they could integrate secure design reviews, security user stories in Fortify on Demand Portal, and also look for possible options to get just one view of risks for given services (Covering Application, Infrastructure, Pen. Test, etc.).

For how long have I used the solution?

I’ve used it since 2010.

What was my experience with deployment of the solution?

We've had no issues with deployment.

What do I think about the stability of the solution?

It’s a very stable product. We've had no issues with instability.

What do I think about the scalability of the solution?

It’s scaled for our needs. We've had no issues with un-scalability.

How are customer service and technical support?

Customer Service:

Customer service is excellent.

Technical Support:

The technical support is very good.

Which solution did I use previously and why did I switch?

We've used various other tools, including the Fortify on-premise solution. We chose Fortify on Demand as it is cost effective, scalable, easy to deploy, and helps us to manage our vulnerabilities centrally.

How was the initial setup?

The initial setup was very easy and straightforward. We were able to roll out this service to all our business units.

What about the implementation team?

We performed the installation in-house.

What's my experience with pricing, setup cost, and licensing?

There is no setup cost as it is an on-demand solution. However, if there is any firewall change required for an internal application, we would need to raise that from our end.

Which other solutions did I evaluate?

We considered SonarQube, MSFox, and CodeInspect.

What other advice do I have?

Fully utilize this product and its feature as it covers almost everything required for software security assurance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.