OpenText home page.
Application Security Testing

OpenText Static Application Security Testing (Fortify)

Find and fix security issues early with industry-leading accuracy

OpenText Static Application Security Testing platform dashboard on a computer

Gartner® named OpenText a leader in Application SecurityGet the Magic Quadrant report

Automate security in the CI/CD pipeline

Traditional SAST tools often require tuning and expertise, overwhelming teams with false positives. Others are easy to use, but miss vulnerabilities. OpenText™ Static Application Security Testing (Fortify) (SAST) enables DevSecOps with precise vulnerability detection, broad language support, and seamless CI/CD integration. AI-driven insights help developers prioritize and resolve vulnerabilities efficiently, reducing security risk across the SDLC.

Why OpenText Static Application Security Testing?

Find critical vulnerabilities others miss. OpenText SAST integrates with GitHub, GitLab, Jenkins, Azure DevOps, VS Code, Eclipse, and more to secure code early while keeping developers moving fast.

  • 1,495+
    vulnerability categories assessed
    Across 33+ languages and more than one million individual APIs.
  • 350+
    frameworks supported
    Providing unparalleled breadth and flexibility, ensuring comprehensive security coverage across diverse development environments.
  • 94%
    of OpenText users agree
    OpenText Static Application Security Testing helps them improve their application security program.
    See what customers are saying

Use cases

OpenText SAST delivers comprehensive security across many development languages while integrating with your dev tool of choice. Balance speed and accuracy with custom scan depth, reduce false positives with AI assistance, and scale dynamically.

  • Scan source code as it’s written to catch vulnerabilities before code is merged or released. Find issues in the developer IDE or pull requests before merge. Fixing issues early drastically reduces remediation cost and prevents security debt from accumulating.

  • Embed SAST into DevOps pipelines to automatically block or flag insecure code at each build or deploy stage. This ensures security keeps pace with agile development and doesn’t slow down release velocity.

  • Enforce secure coding practices and detect violations of compliance frameworks like OWASP Top 10, NIST, PCI-DSS, ISO 27001, and more with policy-based scan enforcement and reporting that reduces the risk of audits, fines, or reputational damage from non-compliance.

  • Apply consistent security scanning across both legacy stacks and modern architectures (e.g., microservices, APIs, containers). Static analysis extends to mobile platforms, REST APIs, and modern interfaces. This serves enterprises running hybrid environments that need full-stack security coverage.

  • Use centralized dashboards and customizable reporting to track findings, remediation progress, and team performance to give security leaders the visibility they need to manage risk and communicate status to management and dev teams.

  • Offer actionable guidance, IDE integrations, and in-context remediation advice to help developers fix vulnerabilities faster. Reduce friction between security and dev teams, improve fix rates, and encourage secure coding habits.

    Key features

    OpenText SAST delivers enterprise-grade code security with AI-powered analysis, cloud-native support, and flexible deployment to help organizations reduce risk, streamline compliance, and build secure software at scale.

    A screenshot of products compatible with OpenText Static Application Security Testing.

    Comprehensive language and framework coverage

    Supports 33+ languages, 350+ frameworks, and detection of over 200+ types of secrets in source code. Enables consistent, comprehensive security testing across your entire codebase.

    A screenshot of the OpenText Static Application Security Testing user interface showing a dashboard.

    Flexible deployment options

    Includes options such as the SaaS-based OpenText™ Core Application Security Testing platform, private hosted, which combines SaaS and on-premises features, and off-cloud, which offers full control over the application security testing solution.

    A screenshot of the OpenText Static Application Security Testing user interface.

    Integrated infrastructure-as-code (IaC) scanning

    Provides best-in-class IaC and app security scanning in one platform, supporting Docker®, Kubernetes®, and serverless, all powered by a single core engine.

    A screenshot of the OpenText Static Application Security Testing user interface highlighting release issues.

    AI-powered auditing and remediation

    Accelerates auditing and vulnerability detection, paired with automated code fixes suggestions for SAST vulnerabilities, using OpenText™ Application Security Aviator™, accessible via SaaS and off-cloud.

    A screenshot of the OpenText Static Application Security Testing user interface highlighting token management.

    Next-gen SAST engine

    Offers coverage across 33+ languages, 1,495+ vulnerability categories, 350+ frameworks, and over 1 million APIs.


    Comprehensive language and framework coverage

    OpenText SAST provides accurate support for 33+ major languages and their frameworks, with agile updates backed by the industry-leading Software Security Research (SSR) team

    SAP ABAP logoSAP ABAP
    Action Script logoAction Script
    Angular logoAngular
    Apex logoApex
    Microsoft ASP logoMicrosoft ASP
    Bicep logoBicep
    CSharp logoCSharp
    C++ logoC++
    COBOL logoCOBOL
    Cold Fusion logoCold Fusion
    Docker logoDocker
    Go Lang logoGo Lang
    HTML5 logoHTML5
    Java logoJava
    Java Script logoJava Script
    JSON logoJSON
    JSP logoJSP
    Kotlin logoKotlin
    MXML logoMXML
    Net logo.Net
    NETCore logo.NETCore
    PL/SQL logoPL/SQL
    Python logoPython
    Ruby logoRuby
    Scala logoScala
    Swift Trans logoSwift Trans
    T-SQL logoT-SQL
    Terraform logoTerraform
    Type Script logoType Script
    Microsoft Visual Basics logoMicrosoft Visual Basics
    Visual Basic logoVisual Basic
    Windows Mobile logoWindows Mobile
    XML logoXML
    YAML logoYAML

    Accelerate the value of OpenText Static Application Security Testing

    Deployment

    OpenText offers deployment choice and flexibility for OpenText Static Application Security Testing.

    Professional Services

    OpenText Professional Services combines end-to-end solution implementation with comprehensive technology services to help improve systems.

    Partners

    OpenText helps customers find the right solution, the right support, and the right outcome.

    Communities

    Explore our OpenText communities. Connect with individuals and companies to get insight and support. Get involved in the discussion.

    Take the next step

    Interested in learning more? An OpenText expert is ready to help.

    Contact us