Try our new research platform with insights from 80,000+ expert users
it_user326421 - PeerSpot reviewer
Solution Security Architect with 1,001-5,000 employees
Real User
It has added a very quick turnaround for security code reviews, allowing us to integrate this function into the overall development and testing lifecycle.

What is most valuable?

  • It's On-Demand, and cloud-based which is well suited to occasional and price-conscious use.
  • Fast turn-around allows for easy integration into the development process without any major impact on development efforts.

How has it helped my organization?

It has added a very quick turnaround for security code reviews which allowed us to integrate this (formerly missing) function into the overall development and testing lifecycle.

What needs improvement?

It needs to support more languages.

For how long have I used the solution?

I've used it for three months.

Buyer's Guide
OpenText Core Application Security
August 2025
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,140 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and support?

Excellent – from the PoC through setup and implementation; we received timely and knowledgeable support whenever we need it.

Which solution did I use previously and why did I switch?

We tried to do it by hand (which was very time consuming and error-prone) and some tools built-in to Visual Studio (which was not widely accepted by individuals).

How was the initial setup?

We had some issue with logins and account setups, but received excellent support.

What about the implementation team?

We implemented it ourselves with the help of HP.

What was our ROI?

Don’t know since the project got cancelled.

What other advice do I have?

Take advantage of the free trial and conduct a meaningful PoC. Get a buy-in from upper management early and co-ordinate with all stakeholders (e.g. developers, testing and/or QA groups).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Consultant
Leaderboard
It provides an independent review of third-party applications, allowing organizations to test software before purchasing. But try the free version first as there's no "right" way to measure ROI.

What is most valuable?

I was able to quickly pass compliance with HIPAA.
Correlated static and dynamic results with detailed priority guidance.
Accurate results, tailored to each application.
All results manually reviewed by application security experts .
Central testing program management for all applications.

How has it helped my organization?

HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software. Third-party vendors can upload the source code and/or provide a URL, review the results, and then publish a report back to their customer.

This service compels commercial vendors to take action to proactively fix vulnerabilities, while allowing them to remain in control of their applications. Security professionals can demand that high-priority problems be addressed and verified during the procurement or upgrade process, prior to acceptance. HP Fortify on Demand serves as an independent third-party solution to conduct unbiased analysis of applications and provide a detailed tamper-proof report back to the security team.

What needs improvement?

You are going to like the new detailed reporting. It can correlate the results from different forms of testing and prioritize them by severity to present the truest representation of application risk.

For how long have I used the solution?

1 year

What was my experience with deployment of the solution?

It was very easy to install and deploy.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No. Scalable infrastructure allows for fast turnaround times and it has no limitations based on lines of code, megabytes, or anything else.

How are customer service and technical support?

Customer Service:

Good

Technical Support:

Good

Which solution did I use previously and why did I switch?

I currently use other solutions. We gave HP Fortify on Demand a try and we are very happy with the results.

How was the initial setup?

Yes. Very easy.

What about the implementation team?

We tried the free version first and then we acquired the software the product website.

What was our ROI?

Keep in mind that the calculation for return on investment and, therefore the definition, can be modified to suit the situation. It all depends on what you include as returns and costs. The definition of the term in the broadest sense just attempts to measure the profitability of an investment and, as such, there is no one "right" calculation. But, I have to say the client is very satisfied.

What's my experience with pricing, setup cost, and licensing?

Try the free version first.

Which other solutions did I evaluate?

I am already using other software. We wanted to try it and it works like a charm.

What other advice do I have?

Trust me, you want to be able to do automated and manual testing on a web application that is live.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
PeerSpot user
Buyer's Guide
OpenText Core Application Security
August 2025
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,140 professionals have used our research since 2012.
reviewer2107677 - PeerSpot reviewer
Cyber Security Specialist at a computer software company with 51-200 employees
Real User
User-friendly, stable, and scalable
Pros and Cons
  • "The solution is user-friendly."
  • "I would like the solution to add AI support."

What is our primary use case?

The solution is used for web application listing, like, SaaS.

What is most valuable?

The solution is user-friendly.

What needs improvement?

I would like the solution to add AI support.

For how long have I used the solution?

I have been using the solution for one month.

What do I think about the stability of the solution?

I give the stability a nine out of ten.

What do I think about the scalability of the solution?

I give the scalability a nine out of ten.

We have three people using the solution in our organization.

How are customer service and support?

I am satisfied with the technical support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used SonarQube which is an open-source solution. We switched because we needed an easy-to-understand and configure UI.

How was the initial setup?

I give the initial setup a nine out of ten. The deployment took a few hours and required one person to implement.

What other advice do I have?

I give the solution a nine out of ten.

I recommend the solution to others and I am totally satisfied with it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer961944 - PeerSpot reviewer
R&D at a tech services company with 51-200 employees
Real User
Effective on-demand feature, easy to use cloud, and great support
Pros and Cons
  • "There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do."

    What is our primary use case?

    We are using Micro Focus Fortify on Demand because in the beginning we were using the on-premise version and it was very limited. We thought we could do everything wanted with the on-premise solution. However, it was not easy to use. 

    We are testing the Micro Focus Fortify on Demand solution to improve security.

    We are using the on-premise version of this solution for the static code for developers. For the dynamic code, we're using Micro Focus Fortify on Demand.

    What is most valuable?

    There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do. We were working with a different solution called SolarCloud previously and it was limited. We are trying to find the right level of security for our needs.

    For how long have I used the solution?

    I have been using Micro Focus Fortify on Demand for approximately eight months.

    How are customer service and support?

    The support is good. Their support is in the Netherlands, sometimes it takes some time for the time zone difference between Latin America and the Netherlands but overall the support is good.

    How was the initial setup?

    The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic. They give you an account and that is all, you use the product.

    The premise solution is more rentable. However, it is asking for a lot of effort in the implementation, administration, and integration in the pipeline. It takes time until the company comes to the right level to be able to manage this product. Even with the right partners in Latin America that work with us, it took some time.

    What about the implementation team?

    We had partners in Latin America that help us integrate the implementation of the Micro Focus Fortify on Demand.

    What's my experience with pricing, setup cost, and licensing?

    The solution is expensive and the price could be reduced.

    What other advice do I have?

    My advice to others is if you choose Micro Focus Fortify on Demand, it's very simple to use. If they choose the on-premise version for the static code, they will need a person to manage it to be sure that it's integrated with all the pipelines that they developed. 

    I rate Micro Focus Fortify on Demand a seven out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2025
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.