OpenText 拥有数十年的专业经验,可帮助您解锁数据、连接人员和流程,并以信任为 AI 提供动力
以全新方式查看信息
能够理解您的业务、数据和目标的 AI
利用 AI 内容管理和智能 AI 内容助手实现高效工作
实现更快的应用交付、开发和自动化软件测试
提升客户沟通和体验,助力客户成功
让用户、服务代理和 IT 人员能够找到他们所需的答案
在整个供应链中解锁 AI 驱动的知识、洞察与引导式行动
以全新方式查看信息
能够理解您的业务、数据和目标的 AI
利用 AI 内容管理和智能 AI 内容助手实现高效工作
实现更快的应用交付、开发和自动化软件测试
提升客户沟通和体验,助力客户成功
让用户、服务代理和 IT 人员能够找到他们所需的答案
在整个供应链中解锁 AI 驱动的知识、洞察与引导式行动
一次连接,即可通过安全的 B2B 集成平台触达一切
通过 AI 驱动的 DevOps 自动化、测试和质量,更快地交付更优质的软件
利用令人难忘的客户体验重新构想对话
获得所需的清晰度,以降低 IT 运营的成本和复杂性
Extend the value of your OpenText solutions by building integrations, automation and custom experiences
使用 OpenText 云 API 按自己的方式构建,这些 API 可创建实时信息流,从而支持自定义应用程序和工作流
安全信息管理与可信的 AI 相结合
在这里,您可以使用数据语言构建、部署和迭代代理
一套用于帮助摄取数据和自动化元数据标记,以推动 AI 发展的工具
一套使治理具有主动性和持久性的服务和 API
专业服务专家助您踏上 AI 之旅
以全新方式查看信息
能够理解您的业务、数据和目标的 AI
利用 AI 内容管理和智能 AI 内容助手实现高效工作
实现更快的应用交付、开发和自动化软件测试
提升客户沟通和体验,助力客户成功
让用户、服务代理和 IT 人员能够找到他们所需的答案
在整个供应链中解锁 AI 驱动的知识、洞察与引导式行动

Cut application risk without slowing releases. OpenText Application Security gives your teams the coverage, accuracy, and flexibility to secure code, meet compliance, and keep the business moving.
See post-quantum cryptography risks in source code and TLS 1.3 configurations in one integrated view without stitching together separate tools.
Start with early indicators, then tighten policy when your program is ready so teams stay focused on current priorities instead of future risks.
Detect RSA and DSA usage (starting with Java) and tie findings to code owners to simplify migration planning and assign clear remediation paths.
Identify servers that don’t support hybrid post-quantum key exchange in TLS 1.3 (for example, X25519MLKEM768) and validate configuration updates with runtime scans.
Control when and how post-quantum detection runs using SAST feature flags and informational DAST findings to balance planning with delivery speed.
Plan confidently with a forward roadmap that evolves with NIST standards, key length best practices, and broader language coverage.
Crypto risk hides when SAST findings and TLS settings are siloed across teams. OpenText connects both views so teams can inventory exposure and focus fixes during audits and planning.
Post-quantum alerts can overwhelm teams as risk timelines shift, especially near release freezes. Noise-aware controls help teams phase in detection and scale policies when ready.
Teams often don’t know where quantum-vulnerable algorithms live in legacy code or libraries. OpenText automates discovery, builds a real backlog, and maps findings to owners.
TLS risks can stay hidden across complex environments, delaying readiness. OpenText Dynamic Application Security Testing (DAST) flags missing hybrid PQC handshakes so teams can prioritize and validate upgrades.
Solve business challenges with OpenText
OpenText Consulting Services combines end-to-end solution implementation with comprehensive technology services to help improve systems




Quantum Ready Application Security combines Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify cryptographic algorithms that are secure against classical attacks but will be vulnerable to future quantum computers. SAST scans your code for vulnerable crypto patterns while DAST checks TLS 1.3 configurations for missing hybrid post quantum key exchanges like X25519MLKEM768.
OpenText SAST uses optional post quantum detection rules to flag algorithms that rely on hardness assumptions broken by quantum computers. When the PQC feature flag is enabled, SAST identifies instances of RSA or DSA usage in your code. Results show exactly where these algorithms appear so you can build a cryptographic inventory and plan migrations.
The first release of post quantum rules focuses on RSA and DSA. SAST flags code that generates or uses RSA or DSA keys—algorithms known to be vulnerable to Shor’s quantum factoring algorithm. OpenText’s roadmap extends coverage to other legacy algorithms and key exchange protocols as standards evolve.
Yes. Post quantum detection is disabled by default to reduce noise for organizations not yet planning migrations. To enable it, set the [com.fortify.sca.rules.enablePQCRules] feature flag. When disabled, SAST reports only traditional crypto vulnerabilities; when enabled, it adds RSA and DSA findings for inventory purposes.
OpenText DAST introduces a new category called “Insecure Transport: Missing PQC Resilient Key Exchange.” It checks whether a web server’s TLS 1.3 configuration supports hybrid post quantum key exchange options, such as X25519MLKEM768. If none are offered, DAST generates an informational finding, so teams know which endpoints need configuration updates.
To balance security and practicality, OpenText makes post quantum detection opt in and low severity. SAST’s quantum related rules are behind a feature flag so you decide when to start generating findings. DAST reports missing hybrid key exchanges as informational rather than high severity, ensuring teams can plan without blocking releases.
No. This solution helps you find and plan for cryptographic migrations; it does not implement new post quantum encryption. SAST and DAST surface where legacy algorithms are used and where TLS lacks hybrid PQC support, allowing you to prepare a migration strategy. It is about planning and prioritization, not an automatic replacement of encryption schemes.
OpenText plans to expand its post quantum capabilities beyond RSA and DSA. Future releases will detect additional quantum vulnerable algorithms and key exchange protocols, analyze key lengths (e.g., highlighting when AES 128 is inadequate in a post quantum context), and extend post quantum detection across more programming languages.

