OpenText recognized as a Customers' Choice by Gartner®Get the report
Identify application security issues at the source, prioritize critical risks, and get detailed guidance to fix them
OpenText™ Static Application Security Testing (Fortify) (SAST) identifies and remediates security vulnerabilities in source code with precision. Extensive language coverage and seamless CI/CD integration streamline security across the SDLC. Advanced static code analysis and AI-driven insights prioritize risks and enable developers to resolve vulnerabilities efficiently, reducing overall security risk.
Catch code vulnerabilities early, reducing development time and cost while integrating seamlessly into the SDLC. Identify twice as many vulnerabilities and reduce false positives, enabling faster, more efficient remediation.
Integrating [OpenText SAST] has reduced the efforts required for code review, and the quality it provides is better than other market tools.
Automating our security testing with [OpenText], we've covered almost 100% of our CI/CD pipelines, which amount to several tens of thousands, with SAST scans.
By integrating [OpenText SAST] into our CI/CD pipelines, we automate security testing and identify vulnerabilities early, reducing remediation costs and accelerating secure software delivery.
…our testing efforts have been easier to quantify and manage both for first-time scans and periodic scans of software modules (at the review level when after developer teams turn the FPRs in).
[OpenText] helped us in finding vulnerabilities in our developer's code. The recommendation for each finding helped our developer to fix their code quickly. This will help secure the products we publish.
OpenText SAST delivers comprehensive security across many development languages while integrating with your dev tool of choice. Balance speed and accuracy with custom scan depth, reduce false positives with AI assistance, and scale dynamically.
Gain support for 1,657 vulnerability categories across 33+ languages, spanning more than one million individual APIs.
Embed security into the application development tools you use with OpenText SAST’s integration ecosystem.
Gain control of the speed and accuracy of SAST by tuning the depth of the scan and minimizing false positives with Audit Assistant.
Dynamically scale SAST scans up or down to meet the changing demands of the CI/CD pipeline.
Achieve comprehensive shift-left security for cloud-native applications—from IaC to serverless—in a single solution.
Choose the deployment option that’s right for you: on premises, in the cloud, or AppSec-as-a-service.
OpenText SAST integrates seamlessly with your workflow, offering flexible deployment options, multi-language support, real-time analysis, and AI-driven automation to enhance application security without sacrificing speed
Supports ABAP/BSP, ActionScript, Apex, ASP.NET, C# (.NET), C/C++, Classic, ASP (with VBScript), COBOL, ColdFusion CFML, Go, HTML, Java (including Android), JavaScript /AJAX, JSP, Kotlin, and more.
Includes options such as the SaaS-based OpenText™ Core Application Security Testing platform, private hosted, which combines SaaS and on-premises features, and off-cloud, which offers full control over the application security testing solution.
Provides structural and configuration analyzers that are purpose built for speed and efficiency. Security Assistant only returns high-confidence findings with immediate results in the IDE.
Provides automated audit results in minutes, minimizing auditor workload and prioritizing issues with accurate and consistent audit results.
Enables lightweight packaging on the build server and provides a scalable, centralized scanning infrastructure.
OpenText SAST provides accurate support for 33+ major languages and their frameworks, with agile updates backed by the industry-leading Software Security Research (SSR) team
OpenText offers deployment choice and flexibility for OpenText Static Application Security Testing.
OpenText Public Cloud (Multi-Tenant SaaS)
Off Cloud, on-premises software, managed by your organization or OpenText
OpenText Private Cloud (Single Tenant) on OpenText Cloud, AWS, GCP, or Azure
API from OpenText Developer Cloud
OpenText Professional Services combines end-to-end solution implementation with comprehensive technology services to help improve systems.
Your journey to success
Consulting Services
NextGen Services
Customer Success Services
OpenText helps customers find the right solution, the right support, and the right outcome.
Find a Partner
Application Marketplace
Strategic Partners
Explore our OpenText communities. Connect with individuals and companies to get insight and support. Get involved in the discussion.
OpenText community
OpenText recognized for Application Security Testing on Gartner® Peer Insights™︎.
Read the blogUnderstand the limits of auto-remediation in securing applications.
Read the blogIDC predicts that by 2026, 40% of net-new applications will incorporate AI.
Read the blogTurn SAST findings into learning, helping developers quickly remediate vulnerabilities.
Read the blogSoftware supply chain risk continues to rise—156% year-over-year increase in malicious attacks.
Read the blogOpenText is a Leader in SAST and DAST, and one of the only vendors that moved up in the quadrant.
Read the blogExplore why false positives in SAST tools occur, the trade-offs involved, and how to manage them.
Read the blogUnlock security testing, vulnerability management, and tailored expertise and support
Scan, test, and identify security vulnerabilities in apps and services
Secure smarter, not harder with AI code analysis and code fix suggestions
Take full control of open source security, compliance, and health