Fortify (now OpenText)
About Fortify (now OpenText)
OpenText Cybersecurity provides data security, identity security, and development security tools. It offers detection and investigation capabilities through a unified security approach.
How to evaluate Application Security
This is how the CIOPages Research Team evaluates this category. It is not an assessment of Fortify (now OpenText). It comes from our DevSecOps & Application Security Testing buyer guide.
25%
Finding Accuracy & Risk Prioritization
False-positive and false-negative rates on your own code; reachability analysis (is the vulnerable function actually called?); runtime/exposure context; EPSS/CVSS-based scoring; how a flood of findings collapses to a short, ranked, defensible work queue
20%
Developer Workflow Integration
Native IDE plugins, PR/MR checks and inline comments, SCM (GitHub/GitLab/Bitbucket/Azure DevOps) and CI/CD integration, quality/security gates, credible one-click autofix, and how little context-switching a developer needs to remediate
20%
Scanning Coverage & Engine Depth
SAST, SCA, secrets, IaC, container, and DAST/API coverage; supported languages and frameworks; vulnerability and malicious-package intelligence; SBOM generation and open-source license analysis; scan speed on large monorepos
15%
ASPM & Consolidation
De-duplication and correlation across first- and third-party scanners, code-to-cloud/runtime context, application risk graph or single risk score per app, policy-as-code, and openness to ingesting tools you already own rather than locking you in
10%
AI-Generated Code Security
Detection of AI-assisted/AI-authored code, guardrails for coding-assistant and agentic workflows, security of LLM/MCP integrations and open-source AI models, and whether the platform keeps pace with code generated faster than humans review it
10%
Governance, Compliance & Deployment
RBAC/SSO, audit trails and attestation, policy gates mapped to PCI-DSS/SOC 2/NIST SSDF, SBOM/VEX export, SaaS vs. self-managed/air-gapped and FedRAMP options, and clean API/data export for your own reporting
Other Application Security Vendors
View allRelated Buyer Guides
Our buyer guides across Cybersecurity. Each one compares the main vendors in its category and what buyers weigh up.
CIOPages put this listing together from public sources. It’s information, not an endorsement. How we build listings. Work here? Claim this listing or .
Quick Facts
www.microfocus.com/en-us/cyberres/application-securityCategoryCybersecurity
SubcategoryApplication Security
FoundedNot on file
HeadquartersNot on file
We publish a detail only when we can point at the page it came from. Claim this listing to fill in the rest.