Talk to us
by OpenTextTechBag Intel Page

OpenText Fortify

Your teams ship code every week. The security review shouldn’t arrive months later — OpenText Fortify tests your software three ways — source code, the running app and its open-source parts — on your own servers in India or as the Fortify on Demand service.

SAST, DAST and SCA in one familySelf-host in India or buy as a serviceGartner AST MQ Leader, 2025

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price for SAST, DAST or Fortify on Demand; SCA has a free tier
Quote
Analysts
2025 Gartner Magic Quadrant for Application Security Testing, 11th year per OpenText
Leader
Coverage
OpenText’s count for Fortify SAST, with 350+ frameworks and 1,524+ categories
44+ languages
India
Off-cloud Fortify stays on your servers; the SaaS has no India region listed
Self-host

Quick answer

OpenText Fortify is an application security testing family: SAST across 44+ languages, DAST for web apps and APIs, SCA (formerly Debricked) and Fortify on Demand, which runs the same tests as a service. Gartner named OpenText a Leader in its 2025 Magic Quadrant for Application Security Testing. Self-hosted Fortify keeps code on servers you choose; the SaaS lists no India region. Prices are by quote. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Fortify — SAST, DAST, SCA and Fortify on Demand. The rest of OpenText:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
This page.
You’re here
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Application security testing: SAST, DAST, SCA and Fortify on Demand as a service
Maker
Open Text Corporation, Waterloo, Canada (NASDAQ and TSX: OTEX); CEO Ayman Antoun since April 2026
Lineage
HP, then HPE, then Micro Focus; OpenText since the Micro Focus deal closed in January 2023
Price
Not published; quote only. Fortify SCA has a free tier, and paid tiers are quoted
SaaS licence
Fortify on Demand runs on prepaid Assessment Units, valid for 12 months with no rollover
Coverage
1,524+ vulnerability categories, 44+ languages, 350+ frameworks, 200+ secret types
Deployment
Off-cloud on your servers, private hosted, or SaaS through Fortify on Demand
Analysts
Leader, 2025 Gartner Magic Quadrant for Application Security Testing; OpenText says 11th year
India
Self-host to keep code in India; Fortify on Demand lists Americas, Europe, Australia and Singapore, not India
In India via
TechBag — scoping, Assessment Unit sizing, quote in INR with GST, pilot support
Part 02 · Learn

Understand application security testing before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is application security testing?

Tools that find security flaws in your own software — in the source, in the running app, and in the open-source parts.

An annual pen test and PDF reports vs testing in the pipeline — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAnnual pen test, PDF reportsOpenText Fortify
When flaws are foundIn a pen test weeks before releaseOn commit, in the IDE and the pipeline
What gets testedWhatever the testers had time forSource, running app, APIs and dependencies
Where findings livePDF reports in email threadsOne audited list per app version in SSC
Who removes the noiseDevelopers, by ignoring the reportYour auditors, or OpenText’s expert review
Proof for auditorsRebuilt by hand each yearPCI DSS, OWASP and NIST reports per scan
What it is NOT—A code-quality tool, a repository or a price list

The fastest test: run Fortify SAST on your oldest codebase and DAST on a staging site, then compare the findings with your last pen test.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where source code is analysed

SAST

Fortify SAST and ScanCentral

The static analyser translates and scans source in the IDE, the build or a remote ScanCentral sensor, and writes findings for 1,524+ categories into a results file.

02
Where running apps are attacked

DAST

Fortify DAST (formerly WebInspect)

The dynamic scanner crawls and attacks a running web app or API — REST, GraphQL, gRPC, SOAP — using login macros, and can run from remote ScanCentral DAST sensors.

03
Where findings are triaged

SSC

Software Security Center

SSC gathers SAST, DAST and SCA results per application version for one triage and policy view; DAST reports also map to PCI DSS, OWASP and NIST 800-53.

04
The same tests, run for you

FoD

Fortify on Demand (SaaS)

OpenText runs the scans in an AWS region you pick from its Americas, Europe, Australia and Singapore environments, with optional expert review and manual testing.

Static, dynamic and composition scans feed one triage view — run on your servers or by OpenText as a service.

Part 03 · Evaluate

Nine capabilities. Scan code, test apps, fix.

OpenText Fortify finds security flaws in the code you write, the apps you run and the libraries you ship.

Code
SAST

Deep static analysis

Taint analysis across 44+ languages and more than a million APIs, scored against 1,524+ vulnerability categories, per OpenText.

Code
Secrets and IaC

Keys and templates too

The same scan looks for 200+ secret types in source and checks Docker, Kubernetes and serverless configuration files.

Code
SCA

Open-source risk and SBOMs

Fortify SCA, formerly Debricked, flags vulnerable and badly licensed dependencies and exports CycloneDX SBOMs.

Run
DAST

Attacks the running app

Fortify DAST crawls web apps with recorded login macros, supports MFA logins and reports client-side libraries it finds.

Run
API testing

REST, GraphQL, gRPC, SOAP

API scans import OpenAPI or Swagger definitions and Postman collections, so endpoints with no UI still get tested.

Run
Mobile

Mobile binaries on demand

Fortify on Demand tests compiled iOS IPA and Android APK or AAB files, plus the network and backend APIs they call.

Fix
Aviator

Suggested code fixes

Remediation Aviator proposes a fix for a finding; on Fortify on Demand it is a per-application add-on costing 1 AU.

Fix
Triage

One audit, many scanners

Software Security Center carries audit decisions forward to later scans, so a confirmed false positive stays closed.

Fix
Expert review

People who remove noise

On Fortify on Demand, Security Expert Review strips false positives, and manual DAST adds up to 8 hours of expert testing.

See it, don’t just read it

Watch OpenText Fortify in action

Fortify SAST in a CI/CD pipeline, Remediation Aviator suggesting a fix, DAST login macros, and Sage’s customer story.

OpenText Fortify Unplugged (official)·4:10 demo, April 2026

OpenText SAST Demo: Shift Left Security with CI/CD Integration, SSC, and AI-Powered Analysis

Fortify SAST wired into a CI/CD pipeline, with results landing in Software Security Center.

OpenText Fortify Unplugged (official)·2:39 demo, September 2026

From Finding to Fix: Fortify Remediation Aviator and Agent Skills Demo

Remediation Aviator taking a SAST finding to a suggested code change.

OpenText Fortify Unplugged (official)·3:58 demo, August 2026

Automate DAST login macros with Fortify DAST Aviator

Building the login macro an authenticated DAST scan needs, with AI assistance.

OpenText (official)·2:31 customer story, July 2026

How Sage cut its SAST backlog and remediation time with OpenText Fortify

Sage’s account of working down its static-analysis backlog with Fortify.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Fortify

Pen tests find flaws after the code ships. Fortify finds them while it is written.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Static, dynamic and composition testing from one vendor

Fortify covers SAST, DAST and SCA, and Fortify on Demand adds mobile testing, so findings land in one Software Security Center queue. OpenText claims to be the only provider offering SAST, SCA, DAST, IAST and MAST as services.

02

Depth for large and old codebases

OpenText counts 44+ languages, 350+ frameworks and 1,524+ vulnerability categories for Fortify SAST, which suits estates mixing Java and .NET with older code. Gartner named OpenText a Leader in its 2025 Application Security Testing Magic Quadrant, an 11th year by OpenText’s count.

03

Run it yourself, or have OpenText run it

The same engines run off-cloud on your servers, private hosted, or as Fortify on Demand. Self-hosting keeps source code in an Indian data centre you control; On Demand adds expert review and manual testing for teams with no AppSec staff.

04

Where it stops

No price is published, and Assessment Units lapse after 12 months. Fortify on Demand lists no India environment, and its AI features may process data in other AWS regions of the same geography. Self-hosted scans need build access and tuning.

The idea
Code, running app and libraries tested
The residency
Self-host in India; SaaS has no India region
The analysts
Gartner AST MQ Leader, 2025
Proof, not promises

The numbers behind the platform

1524+ categories
vulnerability categories Fortify SAST assesses, by OpenText’s count
— Vendor
44+ languages
programming languages the static analyser covers, with more than a million APIs
— Vendor
350+ frameworks
frameworks Fortify SAST understands, so data flow is traced through them
— Vendor
200+ secret types
kinds of credentials and keys the SAST scan looks for in source code
— Vendor
11 years
as a Leader in Gartner’s Application Security Testing MQ, per OpenText’s 2025 release
— Analyst
30 days
to download your data after a Fortify on Demand term ends, per OpenText’s service description
— Vendor

What your OpenText Fortify rollout looks like

Week 1Model

List the apps that matter

Rank applications by data held and exposure, note languages and build tools, and decide self-hosted or On Demand.

Week 2Pilot

Scan two real apps

Run SAST on one modern and one older codebase and DAST on a staging site, then compare findings with your last pen test.

Week 3Decide

Tune and triage

Audit the first results in Software Security Center, suppress confirmed false positives and agree severity rules.

Month 2Prove

Put it in the pipeline

Add scans to Jenkins, GitHub, GitLab or Azure DevOps, send issues to Jira, and set which findings block a release.

Month 3Commit

Extend and report

Add SCA and SBOM export, authenticated DAST for each release, and PCI DSS or OWASP reports for your auditors.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
48+ reviews*
82% would recommend
Scan depth4.5
Language coverage4.4
False-positive noise3.6
Ease of setup3.5
Value for money3.6
5★
42%
4★
38%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our core banking code mixes Java with older modules. Fortify parsed all of it, which two lighter scanners we trialled could not.”
AppSec Lead
BFSI
Insurance
“The first full scan raised thousands of issues. Audit work in Software Security Center got us to a backlog developers would accept.”
Security Architect
Insurance
SaaS
“We bought Fortify on Demand application subscriptions because we had no AppSec team. The expert review removed most of the noise.”
Head of Engineering
SaaS
E-commerce
“Recording login macros for DAST took longer than the scans. Once built, the authenticated runs reached pages the crawler had missed.”
QA Manager
E-commerce
Payments
“Auditors wanted PCI DSS evidence for every release. The DAST compliance reports gave us that without a separate pen-test cycle.”
Compliance Manager
Payments
Manufacturing
“Strong engine, slow procurement. Assessment Units were hard to budget, and unused ones lapsed at the end of the year.”
IT Procurement Lead
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application security testing market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Application Security Testing Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText FortifyThis page

Gartner AST Leader in 2025; quote only.

Grid 02 · The architecture

Deployment Choice × Testing Breadth

The grid nobody publishes — how many ways you can run the tool and keep code in India vs how many kinds of testing it does.

Broad but cloud-boundRun-anywhere AppSec suitesPlatform add-onsSelf-hosted code checks
OpenText FortifyThis page

SAST, DAST, SCA and mobile; off-cloud, hosted or SaaS (no India region).

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText Fortify vs the application security testing field

Against SonarQube Server, GitHub Code Security, GitLab Ultimate, JFrog Advanced Security and Qualys Web App Scanning — on coverage, deployment, price, limits, depth and India.

DimensionOpenText FortifySonarQube ServerGitHub Code SecurityGitLab UltimateJFrog Advanced SecurityQualys Web App Scanning
What it isSAST, DAST, SCA, serviceCode quality + SASTCodeQL for GitHub reposTop GitLab tierAdd-on to JFrog XrayCloud DAST
DeploymentOff-cloud, hosted, SaaSSelf-managedGitHub cloud or GHESSaaS, own, or DedicatedSaaS or self-managedSaaS + scanner boxes
Coverage44+ languagesUp to 45 languagesCodeQL, 12 targetsAdvanced SAST: 7 GASAST in 9 languagesWeb apps and APIs
Pricing modelQuote; AUs for SaaSPer instance, by LOCPer active committerPer user, customPer contributing devPer app, by quote
Published entry priceNot publishedNot published$30/committer/monthUltimate: custom priceNot publishedNot published
Included vs add-onAviator, review extraSCA is extraSecrets sold apartSecurity in the tierNeeds Xray tier firstCSAM/EASM separate
Scale limitsOne scan per app at onceSized by lines of codeMetered on committers50,000 CI minutesDeveloper countsLicensed app count
Testing depthStatic + dynamic + SCASAST, secrets, IaCSemantic SAST onlySAST, DAST, SCA, secretsApplicability firstDynamic only
IntegrationsIDEs, CI, JiraFour DevOps platformsGitHub onlyInside GitLab CIIDE, CLI, FrogbotJenkins and API
Governance and SSOSAML, X.509, LDAPSAML; SCIM on Ent.SAML, LDAP or CASPolicies + dashboardsSAML, SCIM, OIDCPlatform roles
India data locationSelf-host; no SaaS hereYour servers in IndiaGHES onlySelf-managed or MumbaiMumbai and PuneIN1 platform
Support24x7, 1-hour targetPaid below 30M LOCVia your GitHub plan24/7 for emergencies24/7 SLA includedNot detailed
Lock-in and exit30 days to exportFree build fallbackTied to GitHubTied to GitLab CITied to JFrog tierTied to TruRisk
Best fitRegulated, mixed estatesGates on every PRAll-in on GitHubAll-in on GitLabAlready on JFrogWeb estates, PCI
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText Fortify if…

  • ✓You need static, dynamic and composition testing from one vendor, with one place to audit and report findings
  • ✓Your codebase mixes modern and older languages, and lighter scanners miss parts of it
  • ✓You want the choice of self-hosting in India or buying testing as a service with expert review

Compare alternatives if…

  • ✓Your code and pipelines all live in GitHub or GitLab, where Code Security or Ultimate scans without another vendor
  • ✓You want a price you can read first — GitHub lists $30 per active committer a month for Code Security
  • ✓You want a SaaS region in India — GitLab Dedicated, JFrog and Qualys list one; Fortify on Demand does not

Do not expect…

  • ✓A published price, or Assessment Units that carry over past 12 months
  • ✓A Fortify on Demand environment in India
  • ✓Code-quality gates or an artifact repository — Fortify finds security flaws only

OpenText Fortify is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do late security findings cost you?

Drag the sliders (developers committing code; developer-hour cost). Estimates model developer time lost to security flaws found late — in a pre-release pen test or an audit — at an assumed 1.5 hours per developer a year, with 70% of it removed by scanning in the IDE and pipeline. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cost of late security fixes
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: OpenText prints no price for Fortify SAST, DAST or Fortify on Demand. On Demand is bought as prepaid Assessment Units that last 12 months — a year of Static scans on one app is 4 AUs — and Fortify SCA has a free tier. TechBag sizes the units or licences against your app list and quotes in INR with GST.

Self-hosted Fortify

Best when code must stay in India

  • SAST, DAST and SCA on your servers
  • Quote only; no public price
  • Your team runs scans and triage

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Fortify on Demand

Best for teams without AppSec staff

  • Prepaid Assessment Units, 12 months
  • Expert review and manual testing
  • No India environment listed

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Deployment

Self-hosted, private hosted or Fortify on Demand? On Demand lists Americas, Europe, Australia and Singapore, not India.

2
Languages

Is every language and framework in your estate on OpenText’s supported list? Test your oldest codebase first.

3
Scope

Do you need SAST only, or DAST, SCA and mobile testing too? Each is a separate line in the quote.

4
Licensing

On Demand: how many Assessment Units, application or developer subscriptions? Unused AUs lapse after 12 months.

5
Pipeline

Which CI tools and IDEs must run scans, and which findings will block a build or a release?

6
Triage

Who audits findings: your AppSec staff in Software Security Center, or OpenText’s Security Expert Review?

7
AI features

Will you enable Remediation Aviator? It uses a third-party LLM that may process in other regions of one geography.

8
Commercials

Does the quote list products, units, term and support? Ask TechBag for INR with GST and the renewal terms.

FAQ

Questions buyers ask

Fortify is OpenText’s application security testing family. Fortify SAST reads source code, Fortify DAST attacks running web apps and APIs, and Fortify SCA checks open-source dependencies. Fortify on Demand delivers the same tests as a service, with optional expert review and mobile app testing.

Ready to evaluate OpenText Fortify?

Model what late security findings cost your developers, or let a TechBag advisor scope a pilot that scans two of your own codebases.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.