Fortify Software
Fortify Software is an enterprise application security testing platform offering SAST, DAST, SCA, ASPM, and AI-powered remediation tools, serving large enterprises and federal agencies with FedRAMP-certified DevSecOps workflows under OpenText Corporation.
- Company typePrivate
- Founded2003
- HeadquartersSan Mateo, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Fortify Software does
Fortify Software is an enterprise application security testing platform that enables organizations to detect, prioritize, and remediate security vulnerabilities across the software development lifecycle. Its core product suite comprises OpenText Fortify SAST (static code analysis), Fortify DAST (dynamic analysis of live applications), Fortify Software Composition Analysis (open-source and third-party risk, with an Open Source Select database of over 40 million projects), and Fortify on Demand (managed cloud-based testing). Layered on top are Application Security Posture Management (ASPM) for unified risk prioritization, the Aviator AI suite (Remediation Aviator for AI-generated code fixes and DAST Aviator for AI-automated authenticated scanning), and GenAI Application Security for securing AI-generated code and LLM-enabled applications. The platform integrates with major IDEs (Eclipse, Visual Studio, VS Code, JetBrains), source-control systems (GitHub, GitLab, Bitbucket), and CI/CD and cloud platforms (AWS, Google Cloud, Oracle, Gradle, Apache Ant).
Fortify serves enterprise and public-sector customers with complex DevSecOps workflows, including the U.S. Air Force, DATEV eG, and UD Trucks. It holds FedRAMP Moderate authorization and NIST 800-53 control mappings, positioning it for federal and regulated-industry buyers. Go-to-market is enterprise field sales with quote-based subscription licensing, annual billing, and flexible deployment across on-premises, private cloud, and public cloud; AWS Marketplace provides a procurement alternative. Pricing is not publicly disclosed.
Fortify was founded circa 2002–2003 as an independent company, was acquired by Micro Focus in 2010, and became part of OpenText Corporation (NASDAQ: OTEX) following OpenText's 2023 acquisition of Micro Focus's software business. It now operates as the OpenText Fortify product line within OpenText's broader Application Security Testing and Cybersecurity portfolio and is no longer an independently reported business entity.
Fortify Software firmographics
Firmographics- Name
- Fortify Software
- Legal name
- OpenText Corporation
- Website
- https://fortify.com
- Company type
- Private
- Founded year
- 2003
- Operating status
- Acquired
- Headcount range
- 101–250 employees
- Short description
- Fortify Software is an enterprise application security testing platform offering SAST, DAST, SCA, ASPM, and AI-powered remediation tools, serving large enterprises and federal agencies with FedRAMP-certified DevSecOps workflows under OpenText Corporation.
- Ownership category
- akta.pro rank
Fortify Software industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Software Publishers (513210), Other Computer Related Services (541519)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD), Code & Repository Security (Git Security, Code Integrity) (HDADACAG), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI), Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where Fortify Software is headquartered
LocationHeadquarters
- HQ city
- San Mateo
- HQ country
- United States
- HQ region
- North America
Markets served
Fortify Software business model
Business model- GTM type
- B2B
- Offering type
- Software
Revenue model
- Software Licenses and Subscriptions: Enterprise licensing model for Fortify security testing tools including SAST, DAST, and SCA products. Offered as on-premises, private cloud, or public cloud deployment options.
- Cloud-based Security Testing Services: Fortify on Demand provides managed security testing services with vulnerability management and expert support
- Professional Services: Deployment, integration, and consulting services for enterprise implementation
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with flexible deployment options |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Fortify Software product offering
Product offeringCore offering
Fortify Software is an application security testing (AppSec) product line, marketed as OpenText Fortify, that helps enterprises identify, prioritize, and remediate security vulnerabilities in source code, running applications, and open-source dependencies. The platform combines static (SAST), dynamic (DAST), and software composition analysis (SCA) with ASPM, code signing, SBOM generation, and AI-assisted remediation to secure the software development lifecycle. Offerings are available as on-premises, private cloud, and SaaS deployments for developers, security teams, and government organizations.
Product overview
Fortify Software operates as part of OpenText's Application Security Testing portfolio, offering an enterprise application security platform rather than a single product. The platform consists of a core suite of security testing products including OpenText Fortify SAST (static code analysis), Fortify DAST (dynamic application security testing), Fortify on Demand (cloud-based testing), and Fortify Software Composition Analysis (SCA) for open source risk management. Additional modules include Fortify DAST Aviator (AI-powered login macro automation), Fortify Remediation Aviator (AI-generated code fixes), Fortify Open Source Select (open source project database), and Fortify ASPM (unified security posture management). The platform integrates with IDEs (Eclipse, Visual Studio, VS Code, JetBrains), source control (GitHub, GitLab, Bitbucket), CI/CD pipelines (AWS, Google Cloud, Oracle), and build tools (Gradle, Apache Ant), with optional Secure Code Warrior training integration. GenAI application security capabilities are available to secure AI-generated code and LLM-enabled applications.
Differentiator
Problem solved
Functional benefit
Brands
- Fortify on Demand: Cloud-based security testing, vulnerability management, and tailored expertise and support service.
- Fortify SAST
- Fortify DAST
- Fortify DAST Aviator
- Fortify Open Source Select
- Fortify Remediation Aviator
- Fortify Software Composition Analysis
Products and services
- OpenText Fortify Application Security Testing Comprehensive enterprise application security testing platform that combines static analysis, dynamic analysis, software composition analysis, and application security posture management to help security and development teams find, prioritize, and remediate software vulnerabilities across the full software development lifecycle.
- OpenText Fortify Static Code Analyzer (SAST) Static application security testing solution that scans proprietary source code to detect security vulnerabilities in more than 33 languages with high accuracy, designed for security analysts, developers, and AppSec teams in enterprises and government agencies.
- OpenText Fortify on Demand Managed cloud-based application security testing service that combines static, dynamic, and mobile application security testing, plus deep expert review and tailored remediation guidance, targeted at organizations wanting AppSec as a subscription service.
- OpenText Fortify WebInspect (DAST) Dynamic application security testing tool that scans running web applications and APIs to identify security vulnerabilities in production and pre-production environments, used by security professionals and penetration testers.
- OpenText Fortify Software Composition Analysis (SCA) Software composition analysis solution that identifies known vulnerabilities, license and security risks, and outdated components in open-source and third-party dependencies, providing SBOM generation for development, security, and legal/compliance teams.
- OpenText Fortify Application Security Posture Management (ASPM) Application security posture management offering that centralizes and normalizes results from multiple Fortify and third-party AppSec tools, applies risk context, and helps security leaders prioritize remediation across the application portfolio.
- OpenText Fortify ScanCentral Centralized orchestration engine for static analysis that allows distributed scan execution across CI/CD pipelines, helping development and security teams run scans at scale within enterprise DevOps environments.
- OpenText Fortify DAST Aviator AI-augmented dynamic application security testing service launched in 2025 that uses generative AI to streamline DAST scans and remediation, targeted at security teams needing faster, automated black-box testing.
- OpenText Fortify Remediation Aviator AI-powered remediation assistant launched in 2025 that generates contextual code fixes and remediation guidance for vulnerabilities identified by Fortify, designed to help developers resolve issues faster.
- OpenText Fortify Open Source Select Open-source component curation and risk management offering that helps organizations approve and govern use of open-source libraries based on security, licensing, and quality data, targeted at development and legal teams.
- OpenText Fortify GenAI Application Security Application security offering focused on securing generative AI-based applications, including AI-driven code generation and LLM-enabled systems, targeted at enterprises deploying GenAI in production.
Quantifiable outcome
- Reduce vulnerability remediation cost by detecting and fixing security issues early in the coding process
- +1 more outcomes
Companies that use Fortify Software
Customer profileNamed customers3 records
Segments3 records
Fortify Software technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability6 records
Feature8 records
Fortify Software partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core and flagship.
- EclipsecoreEclipse IDE integration for Fortify static code analysis, allowing developers to scan code directly within the development environment
- Microsoft Visual StudiocoreVisual Studio IDE plugin for Fortify security scanning integrated into Microsoft development environment
- Visual Studio CodecoreVS Code extension for Fortify static code analysis enabling security scanning in popular code editor
- JetBrainscoreJetBrains IDE integration for Fortify security scanning across IntelliJ, PyCharm, and other JetBrains tools
- GitHubcoreGitHub integration for Fortify scanning within GitHub workflows and pull request checks
- GitLabcoreGitLab integration for security scanning in CI/CD pipelines with Fortify scan capabilities
- BitbucketcoreBitbucket integration for security scanning in Atlassian-based development workflows
- Amazon Web ServicescoreAWS Marketplace listing and cloud deployment support for Fortify on OpenText private cloud service
- Google CloudcoreGoogle Cloud deployment support and integration for Fortify application security platform
- SAPflagshipStrategic partnership for enterprise application integration between OpenText content management and SAP solutions
- MicrosoftflagshipStrategic partnership for Microsoft integration across Azure, Office 365, and enterprise applications
- SalesforceflagshipSalesforce integration for connecting transactional data and unstructured content
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
Fortify Software competitors and assessment
Company assessmentDirect peers
- Synopsys: Synopsys is the closest direct competitor through its Software Integrity Group, offering Coverity (SAST), Black Duck (SCA), and Seeker (DAST/IAST). It competes head-to-head with Fortify in enterprise AppSec deals and is also a Gartner Magic Quadrant Leader.
- Checkmarx: Checkmarx provides an enterprise AppSec platform with SAST (CxSAST), SCA (CxSCA), and IaC security, targeting developer-friendly enterprise adoption. It is one of Fortify's primary direct competitors in Gartner's Application Security Testing Magic Quadrant.
- Veracode: Veracode (now part of Tenable) offers a cloud-native AppSec platform spanning SAST, DAST, SCA, and manual penetration testing. It directly competes with Fortify on enterprise AppSec contracts, particularly with mid-market and regulated enterprises.
- Sonar (SonarQube / SonarCloud): Sonar provides code quality and code security analysis (SAST) integrated into developer workflows. It competes directly with Fortify SAST for developer mindshare, particularly in DevOps-first organizations using open-source tooling.
Emerging players
- Snyk: Snyk is a developer-first security platform that began in SCA and has expanded into SAST, IaC, and container security. It is a major emerging competitor to Fortify, particularly winning developer-led adoption via a PLG motion that contrasts with Fortify's enterprise sales approach.
- Mend (formerly WhiteSource): Mend is an AppSec platform with a strong focus on open-source security and license compliance (SCA) and increasingly SAST. It competes with Fortify SCA and Open Source Select in supply-chain security deals for enterprise customers.
- Contrast Security: Contrast Security pioneered IAST and RASP, providing runtime application security instrumentation. It is an emerging player that overlaps with Fortify DAST and SAST, particularly in Java/.NET-heavy enterprise environments.
- JFrog (with Xray and Curation): JFrog Xray provides SCA, container, and IaC security integrated with the JFrog Artifactory binary repository. It is an emerging player in software supply-chain security, directly competing with Fortify SCA and SBOM capabilities.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security bundles code scanning (CodeQL), secret scanning, and Dependabot (SCA) into GitHub Enterprise. As a broad incumbent inside the dominant developer platform, it represents a structural threat to standalone AppSec vendors like Fortify.
- GitLab (GitLab Secure): GitLab Secure provides integrated SAST, DAST, SCA, container, and IaC scanning within the GitLab DevOps platform. It competes with Fortify by offering AppSec capabilities as part of a broader, integrated DevOps toolchain favored by platform-engineering teams.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Fortify Software social profiles
Digital presenceFortify Software compliance and trust
Trust signalCompliance2 records
Fortify Software financial estimates
Financial estimateRevenue estimate
Valuation estimate
Fortify Software leadership team
Management profileNumber of profiles
Fortify Software funding detail
Funding detailFunding overview
Funding rounds3 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Fortify Software M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Fortify Software
What does Fortify Software do?
Fortify Software is an application security testing (AppSec) product line, marketed as OpenText Fortify, that helps enterprises identify, prioritize, and remediate security vulnerabilities in source code, running applications, and open-source dependencies. The platform combines static (SAST), dynamic (DAST), and software composition analysis (SCA) with ASPM, code signing, SBOM generation, and AI-assisted remediation to secure the software development lifecycle. Offerings are available as on-premises, private cloud, and SaaS deployments for developers, security teams, and government organizations.
Is Fortify Software a public or private company?
Fortify Software is a private company. It is currently acquired.
When was Fortify Software founded?
Fortify Software was founded in 2003. It employs 101 to 250 people.
Where is Fortify Software based?
Fortify Software is headquartered in San Mateo, United States, in the North America region.
How does Fortify Software make money?
Three revenue lines are on record. Software Licenses and Subscriptions are the primary driver. The others are cloud-based Security Testing Services and professional Services.
Who are Fortify Software's main competitors?
Direct peers on record are Synopsys, Checkmarx, Veracode and Sonar (SonarQube / SonarCloud). Emerging players are Snyk, Mend (formerly WhiteSource), Contrast Security and JFrog (with Xray and Curation). Broad incumbents are GitHub Advanced Security and GitLab (GitLab Secure).
Does Fortify Software have an API?
No public API is recorded for Fortify Software.
What industry is Fortify Software in?
Fortify Software's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing). Its NAICS code is 513210 and its SIC code is 7372.