Your teams ship code every week. The security review shouldn’t arrive months later — OpenText Fortify tests your software three ways — source code, the running app and its open-source parts — on your own servers in India or as the Fortify on Demand service.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Fortify — SAST, DAST, SCA and Fortify on Demand. The rest of OpenText:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Tools that find security flaws in your own software — in the source, in the running app, and in the open-source parts.
What consolidation actually replaces, dimension by dimension.
| Dimension | Annual pen test, PDF reports | OpenText Fortify |
|---|---|---|
| When flaws are found | In a pen test weeks before release | On commit, in the IDE and the pipeline |
| What gets tested | Whatever the testers had time for | Source, running app, APIs and dependencies |
| Where findings live | PDF reports in email threads | One audited list per app version in SSC |
| Who removes the noise | Developers, by ignoring the report | Your auditors, or OpenText’s expert review |
| Proof for auditors | Rebuilt by hand each year | PCI DSS, OWASP and NIST reports per scan |
| What it is NOT | — | A code-quality tool, a repository or a price list |
The fastest test: run Fortify SAST on your oldest codebase and DAST on a staging site, then compare the findings with your last pen test.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The static analyser translates and scans source in the IDE, the build or a remote ScanCentral sensor, and writes findings for 1,524+ categories into a results file.
The dynamic scanner crawls and attacks a running web app or API — REST, GraphQL, gRPC, SOAP — using login macros, and can run from remote ScanCentral DAST sensors.
SSC gathers SAST, DAST and SCA results per application version for one triage and policy view; DAST reports also map to PCI DSS, OWASP and NIST 800-53.
OpenText runs the scans in an AWS region you pick from its Americas, Europe, Australia and Singapore environments, with optional expert review and manual testing.
Static, dynamic and composition scans feed one triage view — run on your servers or by OpenText as a service.
OpenText Fortify finds security flaws in the code you write, the apps you run and the libraries you ship.
Taint analysis across 44+ languages and more than a million APIs, scored against 1,524+ vulnerability categories, per OpenText.
The same scan looks for 200+ secret types in source and checks Docker, Kubernetes and serverless configuration files.
Fortify SCA, formerly Debricked, flags vulnerable and badly licensed dependencies and exports CycloneDX SBOMs.
Fortify DAST crawls web apps with recorded login macros, supports MFA logins and reports client-side libraries it finds.
API scans import OpenAPI or Swagger definitions and Postman collections, so endpoints with no UI still get tested.
Fortify on Demand tests compiled iOS IPA and Android APK or AAB files, plus the network and backend APIs they call.
Remediation Aviator proposes a fix for a finding; on Fortify on Demand it is a per-application add-on costing 1 AU.
Software Security Center carries audit decisions forward to later scans, so a confirmed false positive stays closed.
On Fortify on Demand, Security Expert Review strips false positives, and manual DAST adds up to 8 hours of expert testing.
Fortify SAST in a CI/CD pipeline, Remediation Aviator suggesting a fix, DAST login macros, and Sage’s customer story.
Fortify SAST wired into a CI/CD pipeline, with results landing in Software Security Center.
Remediation Aviator taking a SAST finding to a suggested code change.
Building the login macro an authenticated DAST scan needs, with AI assistance.
Sage’s account of working down its static-analysis backlog with Fortify.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Fortify covers SAST, DAST and SCA, and Fortify on Demand adds mobile testing, so findings land in one Software Security Center queue. OpenText claims to be the only provider offering SAST, SCA, DAST, IAST and MAST as services.
OpenText counts 44+ languages, 350+ frameworks and 1,524+ vulnerability categories for Fortify SAST, which suits estates mixing Java and .NET with older code. Gartner named OpenText a Leader in its 2025 Application Security Testing Magic Quadrant, an 11th year by OpenText’s count.
The same engines run off-cloud on your servers, private hosted, or as Fortify on Demand. Self-hosting keeps source code in an Indian data centre you control; On Demand adds expert review and manual testing for teams with no AppSec staff.
No price is published, and Assessment Units lapse after 12 months. Fortify on Demand lists no India environment, and its AI features may process data in other AWS regions of the same geography. Self-hosted scans need build access and tuning.
Rank applications by data held and exposure, note languages and build tools, and decide self-hosted or On Demand.
Run SAST on one modern and one older codebase and DAST on a staging site, then compare findings with your last pen test.
Audit the first results in Software Security Center, suppress confirmed false positives and agree severity rules.
Add scans to Jenkins, GitHub, GitLab or Azure DevOps, send issues to Jira, and set which findings block a release.
Add SCA and SBOM export, authenticated DAST for each release, and PCI DSS or OWASP reports for your auditors.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our core banking code mixes Java with older modules. Fortify parsed all of it, which two lighter scanners we trialled could not.”
“The first full scan raised thousands of issues. Audit work in Software Security Center got us to a backlog developers would accept.”
“We bought Fortify on Demand application subscriptions because we had no AppSec team. The expert review removed most of the noise.”
“Recording login macros for DAST took longer than the scans. Once built, the authenticated runs reached pages the crawler had missed.”
“Auditors wanted PCI DSS evidence for every release. The DAST compliance reports gave us that without a separate pen-test cycle.”
“Strong engine, slow procurement. Assessment Units were hard to budget, and unused ones lapsed at the end of the year.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application security testing market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Gartner AST Leader in 2025; quote only.
The grid nobody publishes — how many ways you can run the tool and keep code in India vs how many kinds of testing it does.
SAST, DAST, SCA and mobile; off-cloud, hosted or SaaS (no India region).
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against SonarQube Server, GitHub Code Security, GitLab Ultimate, JFrog Advanced Security and Qualys Web App Scanning — on coverage, deployment, price, limits, depth and India.
| Dimension | OpenText Fortify | SonarQube Server | GitHub Code Security | GitLab Ultimate | JFrog Advanced Security | Qualys Web App Scanning |
|---|---|---|---|---|---|---|
| What it is | SAST, DAST, SCA, service | Code quality + SAST | CodeQL for GitHub repos | Top GitLab tier | Add-on to JFrog Xray | Cloud DAST |
| Deployment | Off-cloud, hosted, SaaS | Self-managed | GitHub cloud or GHES | SaaS, own, or Dedicated | SaaS or self-managed | SaaS + scanner boxes |
| Coverage | 44+ languages | Up to 45 languages | CodeQL, 12 targets | Advanced SAST: 7 GA | SAST in 9 languages | Web apps and APIs |
| Pricing model | Quote; AUs for SaaS | Per instance, by LOC | Per active committer | Per user, custom | Per contributing dev | Per app, by quote |
| Published entry price | Not published | Not published | $30/committer/month | Ultimate: custom price | Not published | Not published |
| Included vs add-on | Aviator, review extra | SCA is extra | Secrets sold apart | Security in the tier | Needs Xray tier first | CSAM/EASM separate |
| Scale limits | One scan per app at once | Sized by lines of code | Metered on committers | 50,000 CI minutes | Developer counts | Licensed app count |
| Testing depth | Static + dynamic + SCA | SAST, secrets, IaC | Semantic SAST only | SAST, DAST, SCA, secrets | Applicability first | Dynamic only |
| Integrations | IDEs, CI, Jira | Four DevOps platforms | GitHub only | Inside GitLab CI | IDE, CLI, Frogbot | Jenkins and API |
| Governance and SSO | SAML, X.509, LDAP | SAML; SCIM on Ent. | SAML, LDAP or CAS | Policies + dashboards | SAML, SCIM, OIDC | Platform roles |
| India data location | Self-host; no SaaS here | Your servers in India | GHES only | Self-managed or Mumbai | Mumbai and Pune | IN1 platform |
| Support | 24x7, 1-hour target | Paid below 30M LOC | Via your GitHub plan | 24/7 for emergencies | 24/7 SLA included | Not detailed |
| Lock-in and exit | 30 days to export | Free build fallback | Tied to GitHub | Tied to GitLab CI | Tied to JFrog tier | Tied to TruRisk |
| Best fit | Regulated, mixed estates | Gates on every PR | All-in on GitHub | All-in on GitLab | Already on JFrog | Web estates, PCI |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Fortify is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (developers committing code; developer-hour cost). Estimates model developer time lost to security flaws found late — in a pre-release pen test or an audit — at an assumed 1.5 hours per developer a year, with 70% of it removed by scanning in the IDE and pipeline. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: OpenText prints no price for Fortify SAST, DAST or Fortify on Demand. On Demand is bought as prepaid Assessment Units that last 12 months — a year of Static scans on one app is 4 AUs — and Fortify SCA has a free tier. TechBag sizes the units or licences against your app list and quotes in INR with GST.
Best when code must stay in India
Best for a broader rollout
Best for teams without AppSec staff
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Self-hosted, private hosted or Fortify on Demand? On Demand lists Americas, Europe, Australia and Singapore, not India.
Is every language and framework in your estate on OpenText’s supported list? Test your oldest codebase first.
Do you need SAST only, or DAST, SCA and mobile testing too? Each is a separate line in the quote.
On Demand: how many Assessment Units, application or developer subscriptions? Unused AUs lapse after 12 months.
Which CI tools and IDEs must run scans, and which findings will block a build or a release?
Who audits findings: your AppSec staff in Software Security Center, or OpenText’s Security Expert Review?
Will you enable Remediation Aviator? It uses a third-party LLM that may process in other regions of one geography.
Does the quote list products, units, term and support? Ask TechBag for INR with GST and the renewal terms.
Model what late security findings cost your developers, or let a TechBag advisor scope a pilot that scans two of your own codebases.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.