Application Security

OpenText Static Application Security Testing (Fortify)

Find and fix security issues early with industry-leading accuracy

OpenText Static Application Security Testing platform dashboard image

OpenText recognized as a Customers' Choice by Gartner®Get the report

Overview

Identify application security issues at the source, prioritize critical risks, and get detailed guidance to fix them

People reviewing code on monitors

OpenText™ Static Application Security Testing (Fortify) (SAST) identifies and remediates security vulnerabilities in source code with precision. Extensive language coverage and seamless CI/CD integration streamline security across the SDLC. Advanced static code analysis and AI-driven insights prioritize risks and enable developers to resolve vulnerabilities efficiently, reducing overall security risk.

Learn more

Why OpenText Static Application Security Testing?

Catch code vulnerabilities early, reducing development time and cost while integrating seamlessly into the SDLC. Identify twice as many vulnerabilities and reduce false positives, enabling faster, more efficient remediation.

  • Automate
    security in the CI/CD pipeline
    Integrate with CI/CD tools, including Jenkins, Jira, Atlassian Bamboo, Azure DevOps, Eclipse, and Microsoft Visual Studio.
  • 95%
    fewer false positives
    Customize code analysis and apply rules to identify legitimate violations quickly, with multiple options to view results.
  • 25%
    faster development time
    Identity and eliminate vulnerabilities early in development, with accurate results based on the OWASP 1.2b benchmark, improving speed and quality.

Use cases

OpenText SAST delivers comprehensive security across many development languages while integrating with your dev tool of choice. Balance speed and accuracy with custom scan depth, reduce false positives with AI assistance, and scale dynamically.

  • Gain support for 1,657 vulnerability categories across 33+ languages, spanning more than one million individual APIs.

  • Embed security into the application development tools you use with OpenText SAST’s integration ecosystem.

  • Gain control of the speed and accuracy of SAST by tuning the depth of the scan and minimizing false positives with Audit Assistant.

  • Dynamically scale SAST scans up or down to meet the changing demands of the CI/CD pipeline.

  • Achieve comprehensive shift-left security for cloud-native applications—from IaC to serverless—in a single solution.

  • Choose the deployment option that’s right for you: on premises, in the cloud, or AppSec-as-a-service.

    Key features

    OpenText SAST integrates seamlessly with your workflow, offering flexible deployment options, multi-language support, real-time analysis, and AI-driven automation to enhance application security without sacrificing speed

    SAST integrations image

    Developer-friendly language coverage

    Supports ABAP/BSP, ActionScript, Apex, ASP.NET, C# (.NET), C/C++, Classic, ASP (with VBScript), COBOL, ColdFusion CFML, Go, HTML, Java (including Android), JavaScript /AJAX, JSP, Kotlin, and more.

    Deployment option dashboard image

    Flexible deployment options

    Includes options such as the SaaS-based OpenText™ Core Application Security Testing platform, private hosted, which combines SaaS and on-premises features, and off-cloud, which offers full control over the application security testing solution.

    SAST code image

    Real-time code security analysis and results

    Provides structural and configuration analyzers that are purpose built for speed and efficiency. Security Assistant only returns high-confidence findings with immediate results in the IDE.

    SAST release issues image

    Automation with applied machine learning

    Provides automated audit results in minutes, minimizing auditor workload and prioritizing issues with accurate and consistent audit results.

    ScanCentral dashboard image

    ScanCentral

    Enables lightweight packaging on the build server and provides a scalable, centralized scanning infrastructure.


    Integrations

    OpenText SAST provides accurate support for 33+ major languages and their frameworks, with agile updates backed by the industry-leading Software Security Research (SSR) team

    SAP ABAP logoSAP ABAP
    Action Script logoAction Script
    Angular logoAngular
    Apex logoApex
    Microsoft ASP logoMicrosoft ASP
    Bicep logoBicep
    CSharp logoCSharp
    C++ logoC++
    COBOL logoCOBOL
    Cold Fusion logoCold Fusion
    Docker logoDocker
    Go Lang logoGo Lang
    HTML5 logoHTML5
    Java logoJava
    Java Script logoJava Script
    JSON logoJSON
    JSP logoJSP
    Kotlin logoKotlin
    MXML logoMXML
    Net logo.Net
    NETCore logo.NETCore
    PL/SQL logoPL/SQL
    Python logoPython
    Ruby logoRuby
    Scala logoScala
    Swift Trans logoSwift Trans
    T-SQL logoT-SQL
    Terraform logoTerraform
    Type Script logoType Script
    Microsoft Visual Basics logoMicrosoft Visual Basics
    Visual Basic logoVisual Basic
    Windows Mobile logoWindows Mobile
    XML logoXML
    YAML logoYAML

    Accelerate the value of OpenText Static Application Security Testing

    Deployment

    OpenText offers deployment choice and flexibility for OpenText Static Application Security Testing.

    Professional Services

    OpenText Professional Services combines end-to-end solution implementation with comprehensive technology services to help improve systems.

    Partners

    OpenText helps customers find the right solution, the right support, and the right outcome.

    Communities

    Explore our OpenText communities. Connect with individuals and companies to get insight and support. Get involved in the discussion.

    OpenText Static Application Security Testing resources

    Location world icon

    OpenText supports high-quality application release with less expense and effort

    Learn more
    SAP icon

    OpenText protects SAP and customers against software-related financial losses

    Learn more
    Callcredit logo

    Callcredit adds OpenText into development lifecycle

    Learn more
    DATEV eg logo

    OpenText helped reduce complexity and improved development collaboration

    Learn more
    Professional services logo

    Strategic alliance with OpenText lowers TCO while enhancing cyber resilience

    Learn more
    Banking logo

    Custom software solutions boost health management and ensure data compliance

    Learn more
    Hightech logo

    OpenText delivers effective and streamlined application security

    Learn more

    OpenText Static Application Security Testing (SAST)

    Read the data sheet

    Support and documentation

    View the documentation

    OpenText Static Application Security Testing (SAST)

    Read the data sheet

    Support and documentation

    View the documentation
    Person typing on a laptop

    Customers’ Choice

    OpenText recognized for Application Security Testing on Gartner® Peer Insights™︎.

    Read the blog
    Person wearing glasses looking at a computer screen

    Auto-remediation: the future of AppSec?

    Understand the limits of auto-remediation in securing applications.

    Read the blog
    Generative AI image

    Generative AI: A double-edged sword for application security

    IDC predicts that by 2026, 40% of net-new applications will incorporate AI.

    Read the blog
    Mobile and tablet devices

    Smarter, faster AppSec

    Turn SAST findings into learning, helping developers quickly remediate vulnerabilities.

    Read the blog
    Security shield image

    Why SAST + SCA is the key to protecting your organization in 2025

    Software supply chain risk continues to rise—156% year-over-year increase in malicious attacks.

    Read the blog

    OpenText named a Leader in Critical Capabilities by Gartner

    OpenText is a Leader in SAST and DAST, and one of the only vendors that moved up in the quadrant.

    Read the blog

    Why SAST false positives are inevitable

    Explore why false positives in SAST tools occur, the trade-offs involved, and how to manage them.

    Read the blog

    What is static application security testing (SAST)

    Learn more

    Cybersecurity in a Web 3.0 world

    Read the flyer

    5 reasons why SAST + DAST with OpenText makes sense

    Get the reasons

    OpenText SAST tools

    View the community page

    What is static application security testing (SAST)

    Learn more

    Cybersecurity in a Web 3.0 world

    Read the flyer

    5 reasons why SAST + DAST with OpenText makes sense

    Get the reasons

    OpenText SAST tools

    View the community page

    Take the next step

    Interested in learning more? An OpenText expert is ready to help.

    Contact us