17 years helping Canadian businesses
choose better software
What Is Fortify?
Fortify provides a suite of application security solutions that help organizations analyze their open source code, detect vulnerabilities earlier in their development lifecycle, protect against advanced threats and safeguard their data. Fortify delivers extra layers of protection for the most vulnerable application attack surfaces—servers, web applications and data sources like databases, message queues and big data stores.
Who Uses Fortify?
Not provided by vendor
Not sure about Fortify?
Compare with a popular alternative
Fortify
Reviews of Fortify
Average score
Reviews by company size (employees)
- <50
- 51-200
- 201-1,000
- >1,001
Find reviews by score
Fortify is the most widely used product for vulnerability detection in code and security analysis
Comments: Overall, it's a great and must have tool for every organization working on software development.
Pros:
Fortify can be integrated into popular IDEs like Visual Studio, eclipse, IntelliJ Idea. It can also be integrated into GitLab, Jenkins CICD pipeline, bitbucket etc. It makes static code analysis very easy. It supports very wide range of security checks including both static and dynamic code analysis to detect vulnerabilities. Very easy to use and integrate. Very user-friendly dashboard to check all the issues. Good support from Microfocus.
Cons:
It sometimes gives false positives which wastes effort and time of developers. Might be little bit costly for small organizations but used widely by many organizations. Might fail to detect certain vulnerabilities so we cannot fully rely on it.
A Perfect SAST Solution
Comments: A Perfect SAST Solution to implement in an DevSecOps pipeline. The tool is matured and perfect on its own flow.If your budget meets the cost, you can just go for it as it is a perfect SAST solution.
Pros:
The user-friendly UI, easy connection with CI/CD, and excellent customer assistance are all highlighted along with the details of the code analysis of the problems. The fact that this software is compatible with practically all programming languages is what I enjoy most about it.
Cons:
We have not discovered any issues with the tool; rather it is good and extremely comfortable using it, therefore we are pleased with how it has evolved.