We use the tool for static code analysis.
External reviews
External reviews are not included in the AWS star rating for the product.
An user-friendly solution for static code analysis
What is our primary use case?
What is most valuable?
The solution is user-friendly. One feature I find very effective is the tool's automatic scanning capability. It scans replicas of the code developers write and automatically detects any vulnerabilities. The integration with CI/CD tools is also useful for plugins.
The tool's AI feature analyzes security threats and recommends updating the code accordingly. One major issue that AI detected for us was logging issues and hardware vulnerabilities. Fortify On Demand identified these, allowing our developers to address and fix the issues.
What needs improvement?
Fortify on Demand needs to improve its pricing.
For how long have I used the solution?
I have been working with the product for two years.
What do I think about the stability of the solution?
I rate Fortify on Demand's stability an eight out of ten.
What do I think about the scalability of the solution?
I rate the tool's scalability an eight out of ten. My company has around 25 users.
How was the initial setup?
The initial setup experience with Fortify On Demand was straightforward for us. We installed the plugin and integrated it with our existing tools and logins. There was no need for configuration or setup—it was quite simple. The deployment time varies based on the code complexity. Once vulnerabilities are identified, the support team provides the necessary fixes.
What's my experience with pricing, setup cost, and licensing?
Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten.
What other advice do I have?
We use Burpsuite for dynamic code analysis. Fortify on Demand is a good tool for static code analysis. I rate it a nine out of ten.
Identifies critical vulnerabilities and offers good scanning capabilities
What is our primary use case?
I have used Fortify on Demand for security scanning, along with outsourcing to companies that scan our systems and report vulnerabilities. My work has involved securing our APIs and systems.
We use Fortify across all stages of the environment: development, test, and production. We even use it for disaster recovery.
Whenever we deploy our Jenkins pipelines, the system automatically scans our Git repository to fix security vulnerabilities. All the security vulnerabilities are then created as tasks in Jira, so we can fix them as quickly as possible.
How has it helped my organization?
We have added it to our operational toolkit to ensure it's part of our development spectrum. We added it directly into our Jenkins pipelines.
We have some products that are publicly accessible via phone or website. These products need to be extra secure because they rely on firewalls, and hackers could potentially exploit them. Fortify on Demand provided us with valuable information on how to fix a critical API vulnerability.
So, Fortify on Demand identifies critical vulnerabilities. We have two security scans. One is Fortify on Demand, and the other is for an outsourced company. For Fortify, you assign the specific branch of code you want to scan. You can scan the code you're currently deploying through Jenkins pipelines. Since it's external, you can also scan other brands if needed. Otherwise, you can specify which specific brands or smaller branches to scan within your entire codebase.
What is most valuable?
The scanning capabilities, particularly for our repositories, have been invaluable.
What needs improvement?
There is room for improvement in the integration process, especially with the pipeline system, which could be streamlined. Making changes and configuring it for different systems, like desktop environments, is challenging.
For example, Jenkins integration was hard.
Improving the ease of integration would be beneficial.
For how long have I used the solution?
I have been using it since July.
What do I think about the stability of the solution?
It has been a stable solution for me.
What do I think about the scalability of the solution?
For me, it has been scalable enough.
What was our ROI?
It provides good security. It is a backbone for our security needs. So, that's the biggest benefit for us.
What's my experience with pricing, setup cost, and licensing?
There is a licensing model in place.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. I would recommend using it.
Works as a comprehensive security testing tool with an easy upgradation process
What is our primary use case?
The primary use case for Fortify On Demand in our environment revolves around its critical role in sales and desk operations. It helps identify application vulnerabilities from both a source code and web perspective. It directly detects issues such as SQL injection in the source code. It conducts website scans with customizable configurations to examine potential risks and vulnerabilities, which is crucial during software development. We can avoid risks before moving to the production stage.
What is most valuable?
One of the most valuable features of Fortify On Demand is its ability to integrate seamlessly with the DevOps lifecycle, particularly in terms of security testing. Injecting security testing into the DevOps process ensures that security measures are incorporated from the development stage onwards. It aligns with the main objective of DevOps, which is to automate and streamline the software development lifecycle, from code commit to deployment. With automation tools orchestrating the pipeline, tasks such as code compilation, testing, and deployment can be carried out rapidly and efficiently. This results in faster time-to-market for features, reducing deployment times from hours to minutes. It enhances trust from customers and cybersecurity teams, as security measures are built into the software from the outset, increasing confidence in the security.
What needs improvement?
They could provide features for artificial intelligence similar to other vendors like OpenText products.
For how long have I used the solution?
We have been using Fortify on Demand for about three years.
What do I think about the stability of the solution?
I rate the platform's stability as seven out of ten.
How was the initial setup?
The initial setup is complicated. It takes around four to five hours to complete, including installation and scanning. I rate the process a seven out of ten.
What was our ROI?
Fortify On Demand is not highly expensive. It provides options for the number of scans and tests for the on-premise version. The customers utilizing hardware must install the tool for cost-effectiveness and high availability.
What's my experience with pricing, setup cost, and licensing?
The product's cost depends on the type of license. The on-premise licenses are more expensive than the cloud subscriptions. I rate the pricing a six out of ten.
What other advice do I have?
I rate the platform's accuracy for detecting vulnerabilities an eight and a half out of ten. By utilizing Fortify as a comprehensive security testing tool, financial institutions operating at high-security levels gain confidence in the security posture of their applications. It helps deploy and track changes easily as per time-to-time market upgrades.
I advise new users to learn about new features introduced in the last two years. I rate it a nine out of ten.
Great Product
Review form micro focus fortify app
There is no major drawback about this tool.
Best
Safe and Secured Barrier
Additionally, clean-up rules are enforced by this instrument. With the most advanced security research supporting it, this offers the most comprehensive runtime monitoring and protection, as well as the most advanced static and dynamic application security testing solutions.
With the use of this tool, we can promptly detect and address security risks that safeguard data. It guarantees our clients' trust.