Tool integration

OpenText Fortify Integration Guide

Enterprise SAST platform from OpenText

Get a Free API Key

Integrate OpenText Fortify with Vulnetix. Export static analysis results via the FortifyVulnerabilityExporter or GitHub Action.

25+ languagesSaaS platformSARIFCycloneDXSPDX

How Vulnetix compares: better together

Vulnetix does not replace OpenText Fortify. Keep running it. Vulnetix sits on top of OpenText Fortify (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

OpenText Fortify is strongest at its core category and also carries features in SCA, DAST, IaC & Cloud Configuration, Container & Image Scanning, Secret Scanning, MAST, SBOM Generation, License Compliance, just as Vulnetix spans categories.

CapabilityVulnetixOpenText Fortify
Security coverage
SAST (static code analysis)✓ Built-in rules + Semgrep augmentation✓ Core: Fortify Static Code Analyzer, deep dataflow/control-flow, 30+ languages, 1,500+ categories
SCA / dependencies✓ 40+ ecosystems, transitive graph✓ Debricked SCA fully integrated into Fortify on Demand since Feb 2024; transitive dependency analysis
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine✓ WebInspect DAST scans running apps incl. MFA environments; Fortify on Demand DAST
Container & image✓ Image CVEs, base image, Dockerfile~ Container/cloud-native scanning documented alongside IaC/Docker/K8s
IaC / misconfiguration✓ Terraform, k8s, CloudFormation~ IaC, Docker and Kubernetes scanning available in the suite
Secret scanning✓ 1,000+ rules, source + binary + git history~ Secrets/credential detection covered within SAST rule categories
Cloud / CSPM✓ Cloud-posture findings, compliance tab✗
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine~ Fortify on Demand provides mobile (iOS/Android) app assessments
License compliance✓ SPDX, copyleft/AGPL/SSPL policy~ Debricked provides open-source license risk analysis
SBOM generation✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable✓ Debricked exports CycloneDX and SPDX SBOMs; FoD can import 3rd-party CycloneDX
Malware / supply-chain✓ De-duplicated corpus + install-time firewall (25+ registries)✗
Network / infra vuln~ Ingests network scanner output; no native network scanner✗
Fuzzing✗ Ingests fuzzing crashes; no native fuzzer✗
Pentest / bug bounty✗ Ingests pentest/bug-bounty findings; not a testing service✗
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)✓ Correlates every scanner into one prioritised queue with ownership routing~ Fortify SSC / FoD unify SAST, DAST and SCA findings in one AppSec dashboard
Exploit-intel prioritisation✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV✗
Reachability analysis✓ Tree-sitter + CVEAffected; direct/transitive/semantic✗
Versioned VEX + audit trail✓ Immutable OpenVEX/CycloneDX, cosign-signable✗
Safe Harbour autofix✓ Resolves + applies the nearest safe version✓ Aviator AI produces automated code-fix suggestions surfaced as IDE edits
End-of-life policy✓ Flags/blocks past-EOL runtimes & packages✗
SSVC / risk-based policy✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets✗

✓ full · ~ partial · ✗ not covered

What OpenText Fortify does well

Where Vulnetix adds to it: Vulnetix layers on top of Fortify rather than replacing its deep enterprise SAST/DAST engines: it ingests Fortify SAST/DAST/SCA output, dedups it across every other scanner into one prioritised queue, and adds exploit-intel (EPSS, CISA KEV, ESS, LEV), tree-sitter reachability, immutable versioned VEX + audit, SSVC and EOL policy that Fortify's per-tool dashboards don't unify. Vulnetix does not run WebInspect DAST itself: it consolidates its output. Better together: Fortify keeps running the scans, Vulnetix orchestrates and prioritises the results org-wide.

No migration, no rip-and-replace. OpenText Fortify keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise OpenText Fortify results in Vulnetix

Upload OpenText Fortify SARIF, CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

OpenText Fortify documentation ↗

Wire OpenText Fortify into your CI/CD pipeline →