Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews

External reviews are not included in the AWS star rating for the product.
A great component of the SDLC
What do you like best about the product?
We use the HP Fortify on Demand SaaS, this allows us to free up resources from having to spend time maintaining the infrastructure.
The product allows for RBAC, which helps in allowing appropriate access at all levels.
We have implemented a process of Scan-at-Build, this allows us to ensure that continuous testing is performed.
Additionally, we have enabled SSO, so that developers are able to login to check results as well as add commentary information.
The product allows for RBAC, which helps in allowing appropriate access at all levels.
We have implemented a process of Scan-at-Build, this allows us to ensure that continuous testing is performed.
Additionally, we have enabled SSO, so that developers are able to login to check results as well as add commentary information.
What do you dislike about the product?
One thing that I would like to see improved is the capability for the platform to be able to send alerts on detection of findings. This would allow for stakeholders to be made aware, and take action
What problems is the product solving and how is that benefiting you?
We have compliance requirements for code review, and the department runs fairly lean. The product has allowed us to setup continuous testing as well as self-service
Recommendations to others considering the product:
A good option for Static Analysis, helps close the application layer gaps as well as provides reporting
- Leave a Comment |
- Mark review as helpful
Great experience!
What do you like best about the product?
The response time for analysis report is pretty fast and very well detailed. The reports are very granular and the communication with the vendor is pretty much instantaneous.
What do you dislike about the product?
Sometimes the level of effort to fight a "red flag" in the code can be overwhelming. This requires engaging senior level people to agree on something. It feels like going through an audit and having to fight the major discrepancies. That is very time consuming.
What problems is the product solving and how is that benefiting you?
Our code must meet certain security standards that must be validated by a third party such as HPE Fortify. That gives our customers the assurance that our code is secure and optimized to meet their requirements and security standards.
Recommendations to others considering the product:
I would defeinetly recommend this product to anyone looking to validate the security and the quality of the code of any custom application. I probably would recommend the SaS versus the on premises solution.
Best tool for code analysis and security
What do you like best about the product?
They launched new version with very nice User Interface along with many other features. Its a good tool which scan our code and gives us the security issues in our code which can be cause of our application hack by hackers. Its also gives us recommendation in our code to best use.
What do you dislike about the product?
Tool was little slow, like we are opening any issue in tool its taking more time to loading in tool UI.
What problems is the product solving and how is that benefiting you?
Fortify is solving our application security issue by analyzing our code and giving recommendation for security issues in our code.
Powerful but slow
What do you like best about the product?
HPE Fortify's scans are the best in the industry. There isn't a competitor that can match them in their feature suite and the depth of their product. The workflows are designed well and with the UI upgrade, it actually looks decent.
What do you dislike about the product?
Their expertise comes at a cost. Literally, they are expensive. It also requires a special setup to get the application installed and running correctly. In addition, the upgrade process is not clean and can break existing profiles. Usability suffers a bit from the newer UI because trying to get audits done, now requires navigating through more screens.
What problems is the product solving and how is that benefiting you?
This solves the problem of vulnerable software code. The automated process pinpoints problem areas for the organization to address.
Good code scanning tool for code security
What do you like best about the product?
Its a good tool which scan our code and gives us the security issue in our code which can be cause of our application hack. Its also gives us recommendation in our code to best use.
in Recent version they have come up with very nice UI along with many other features.
in Recent version they have come up with very nice UI along with many other features.
What do you dislike about the product?
UI was little slow, like we are opening any issue in tool its taking more time to loading in tool UI.
What problems is the product solving and how is that benefiting you?
Its solving our application security issue by analyzing our code and giving recommendation for security fallback in our code.
showing 31 - 35