Overview
Product Information on OpenText Application Security Aviator (Fortify)
What is OpenText Application Security Aviator (Fortify)?
OpenText Application Security Aviator (Fortify) Pricing
Overall experience with OpenText Application Security Aviator (Fortify)
“Fortify on Demand: Security Solution for Mobile App Vulnerabilities”
“Needs Improvement, Not upto the mark”
About Company
Company Description
OpenText powers and protects information. As a global secure information management provider for businesses, OpenText tools span content management, artificial intelligence (AI), cybersecurity, cloud, and business networks. For over 30 years, OpenText has helped organizations manage and protect their data and documents while modernizing their information architecture. Its integrated hub connects information across departments and applications to enhance employee experience, productivity, and collaboration, while making information structured and searchable through AI, machine learning, and semantic search. In addition, OpenText delivers endpoint security and digital life protection solutions to safeguard businesses against cyberattacks and data breaches.
Company Details
Do You Manage Peer Insights at OpenText?
Access Vendor Portal to update and manage your profile.
Key Insights
A Snapshot of What Matters - Based on Validated User Reviews
Reviewer Insights for: OpenText Application Security Aviator (Fortify)
Performance of OpenText Application Security Aviator (Fortify) Across Market Features
OpenText Application Security Aviator (Fortify) Likes & Dislikes
It's thorough as heck. Checks for over 300 types of vulnerabilities! They do automatic scans, but they also have real people poking around for the tricky stuff. No stone left unturned. Super flexible. You can pick different levels of testing for each app. Got a super important app? Go for the full package. Anything less critical? There's a lighter option. It's not a one-size-fits-all, which is great. Plays nice with our dev process. It gives feedback right to the developers as they're working. No more security being an afterthought or slowing things down. What I dig into the most is how it takes the pressure off our team. It's all in the cloud, so we don't have to mess with setting up and running security tools ourselves. Their experts handle the heavy lifting, and we can focus on making cool features instead of worrying about security all the time. Is it perfect? Probably not, but it's pretty darn close to what we need. If you're losing sleep over mobile app security, give Fortify on Demand a shot. It's made my life a whole lot easier!
Easy to Use.
* Easy to use * If it works as expected it as Good tool to be used but you wont getting it as expected
The turnaround time for the more comprehensive Mobile Assessment can be a bit longer. While thoroughness is appreciated, sometimes we need faster results to keep up with our aggressive development and release schedules. It would be great if they could find a way to speed up the process for the Mobile Assessments without compromising the quality of the manual expert review.
Not up to the mark as expected.Accuracy of the scan is not up to the mark. The product wont work properly as expected. Performance is Average.
Not up to the mark as expected.Accuracy of the scan is not up to the mark. It has high positive rate but we cant find it. The product wont work properly as expected and the customer support wont car about it, If it stops working you need to deep dive to check what causing the issue you'll end up in scan issue or something else. They wont provide the product for the price they quoted.
Top OpenText Application Security Aviator (Fortify) Alternatives
Peer Discussions
OpenText Application Security Aviator (Fortify) Reviews and Ratings
- TECHNICAL MANAGER<50M USDRetailReview Source
Fortify on Demand: Security Solution for Mobile App Vulnerabilities
Fortify on Demand Mobile App Security Testing is a game-changer! 5 stars all the way. Why the top rating? It's simple, it's got everything covered. From the app itself to the network and servers, this thing checks it all. Makes me feel way better about our apps not getting hacked. - Sr Software Test Engineer50M-1B USDIT ServicesReview Source
Needs Improvement, Not upto the mark
Not up to the mark as expected.Accuracy of the scan is not up to the mark. The product wont work properly as expected. Performance is Average. - Senior software test engineer<50M USDIT ServicesReview Source
Need more improvement! Still way to Go!!
Not up to the mark as expected.Accuracy of the scan is not up to the mark. It has high positive rate but we cant find it. The product wont work properly as expected and the customer support wont car about it, If it stops working you need to deep dive to check what causing the issue you'll end up in scan issue or something else. They wont provide the product for the price they quoted . - Security and Risk Management10B+ USDRetail
Dysfunctional Tool, Inadequate Support
An organisation's application security maturity can be measured by automation. For Fortify on Demand, we were coaxed into using their product and service based upon the apparent ease of build server integration using the Jenkins and VSTS plugins. But these plugins have failed a number of times, and getting Fortify Support to address and fix the problems is like trying to move a mountain. There are two types of failures: (1) either the product blatantly stops working or (2) it appears to be working but truthfully -- if you dig deep and know what to look for (this involves downloading scan results and analysing the fpr file), you may find that a lot of files are not being scanned at all. Unfortunately, only a very experience person with Fortify is able to identify (2), and unfortunately Fortify support makes substantial effort to make you do something else (which is very time consuming to you) rather than simply looking at the Fortify backend failures and trying to fix them. What MicroFocus doesn't seem to get is that efficiency needs to be part of a SAST delivery. We continue to struggle with MicroFocus to try to get them to give us what we paid for: if we are using their VSTS plugin, then the code needs to scan and scan in full when it gets uploaded to their backend. However, they seem to think that when their backend fails, the customer should just do something else rather than use their tools. Truthfully, it is quite likely that hundreds of scans from various customers are not working properly, yet these customers are no visibility to it. MicroFocus doesn't seem to care about this - if nobody knows their product is not working, they don't think it is their problem.



