Tool integration

OpenText Fortify Integration Guide

Enterprise SAST platform from OpenText

Get a Free API Key

Integrate OpenText Fortify with Vulnetix. Export static analysis results via the FortifyVulnerabilityExporter or GitHub Action.

25+ languagesSaaS platformSARIFCycloneDXSPDX

How Vulnetix compares: better together

Vulnetix does not replace OpenText Fortify. Keep running it. Vulnetix sits on top of OpenText Fortify (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

OpenText Fortify is strongest at its core category and also carries features in SCA, DAST, IaC & Cloud Configuration, Container & Image Scanning, Secret Scanning, MAST, SBOM Generation, License Compliance, just as Vulnetix spans categories.

CapabilityVulnetixOpenText Fortify
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentationCore: Fortify Static Code Analyzer, deep dataflow/control-flow, 30+ languages, 1,500+ categories
SCA / dependencies40+ ecosystems, transitive graphDebricked SCA fully integrated into Fortify on Demand since Feb 2024; transitive dependency analysis
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engineWebInspect DAST scans running apps incl. MFA environments; Fortify on Demand DAST
Container & imageImage CVEs, base image, Dockerfile~ Container/cloud-native scanning documented alongside IaC/Docker/K8s
IaC / misconfigurationTerraform, k8s, CloudFormation~ IaC, Docker and Kubernetes scanning available in the suite
Secret scanning1,000+ rules, source + binary + git history~ Secrets/credential detection covered within SAST rule categories
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine~ Fortify on Demand provides mobile (iOS/Android) app assessments
License complianceSPDX, copyleft/AGPL/SSPL policy~ Debricked provides open-source license risk analysis
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signableDebricked exports CycloneDX and SPDX SBOMs; FoD can import 3rd-party CycloneDX
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Fortify SSC / FoD unify SAST, DAST and SCA findings in one AppSec dashboard
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe versionAviator AI produces automated code-fix suggestions surfaced as IDE edits
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What OpenText Fortify does well

Where Vulnetix adds to it: Vulnetix layers on top of Fortify rather than replacing its deep enterprise SAST/DAST engines: it ingests Fortify SAST/DAST/SCA output, dedups it across every other scanner into one prioritised queue, and adds exploit-intel (EPSS, CISA KEV, ESS, LEV), tree-sitter reachability, immutable versioned VEX + audit, SSVC and EOL policy that Fortify's per-tool dashboards don't unify. Vulnetix does not run WebInspect DAST itself: it consolidates its output. Better together: Fortify keeps running the scans, Vulnetix orchestrates and prioritises the results org-wide.

No migration, no rip-and-replace. OpenText Fortify keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise OpenText Fortify results in Vulnetix

Upload OpenText Fortify SARIF, CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

OpenText Fortify documentation ↗

Wire OpenText Fortify into your CI/CD pipeline →