OpenText Fortify
Long-established static, dynamic, and interactive application security testing suite, now an OpenText product line after passing through HP and Micro Focus ownership.
Visit Website ↗Overview
Fortify Software was founded in 2003 and built one of the earliest commercial SAST products. It was acquired by Hewlett-Packard in 2010, became part of Micro Focus in 2017, and passed to OpenText when OpenText acquired Micro Focus in 2023. It now operates as OpenText’s Application Security (Fortify) product line rather than as a standalone company.
The platform covers SAST, DAST, IAST, SCA, API security testing, and IaC scanning from one suite, with support for 33+ programming languages, available as SaaS, on-premises, hybrid, or hardened deployments aimed at regulated industries and government agencies.
OpenText reports Fortify was named a Leader in the 2025 Gartner Magic Quadrant for AST for the 11th consecutive year, and cites adoption by more than 3,500 organizations across 78 countries.
Innovation Matrix Assessment
Three ownership changes in 15 years are consistent with a portfolio product receiving steady maintenance rather than aggressive new capability.
Broad language and API coverage plus flexible on-prem/hardened deployment serve regulated and government buyers well, though on-prem-heavy deployment is higher-friction than cloud-native competitors.
As one product line inside a much larger conglomerate, it lacks an independent growth narrative distinct from its parent company.
The most legacy offering in this batch — a long-running static analysis suite absorbed into successive larger portfolios.
11 consecutive years as a Gartner AST Leader and a reported 3,500+ organization customer base, including government and banking.
Its on-prem/hardened/regulated-sector fit keeps it relevant for government and high-security buyers, but less visibly aligned with cloud-native and AI-code trends.
Why CISOs Should Care
For regulated or government environments that require on-premises or air-gapped scanning, Fortify's deployment flexibility and long compliance track record reduce vendor and procurement risk.
What Makes It Different
Deployment flexibility built for regulated and government buyers is its main differentiator, not a novel detection or delivery model.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
Incremental Innovator, near the lower end (~52/100). A durable Gartner Leader with real regulated-sector traction, but the weakest disruption and velocity signals in this batch.
Editorial Note: Claims vs. Verified Findings
Gartner Leader status is independently corroborated. The '100% true positive rate' on the OWASP Benchmark and the 3,500+ organizations/78 countries figures are OpenText-published marketing claims that could not be independently verified.
Sources
Alternatives to OpenText Fortify
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Contrast Security
Instruments applications from within using IAST and RASP to find and block vulnerabilities as code actually executes, rather…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…