Fortify Software
Application security software brand focused on finding and managing vulnerabilities throughout the software development lifecycle.
Last updated August 22, 2026
Overview
Fortify Software is a United States application security software brand established in 2003. The company developed tools intended to identify weaknesses in software before and during deployment, with its portfolio centered on static application security testing, dynamic application security testing, and related software assurance services. Its technology was aimed at development and security teams that needed to analyze source code, test running applications, prioritize vulnerabilities, and support secure development practices across enterprise software environments. The brand became associated particularly with Fortify Static Code Analyzer, a static analysis product that examines software without requiring the program to be executed, and Fortify WebInspect, a dynamic testing product designed to assess running web applications. Fortify also developed research and knowledge assets supporting application security, including the Java Open Review project, the Vulncat vulnerability taxonomy, and security rules used by its analysis products. Researchers connected with the company published work on subjects including JavaScript hijacking, cross-build injection, cross-site scripting prevention, and dynamic taint propagation. The company’s security research contributed to the broader practice of software security assurance and secure coding with static analysis. Fortify introduced Fortify OnDemand in 2011. The service extended the company’s offering beyond installed analysis tools by providing static and dynamic application testing as a service. This helped position Fortify for organizations seeking managed or on-demand security testing rather than relying solely on locally deployed analysis infrastructure. Fortify’s corporate ownership changed several times. Hewlett-Packard acquired Fortify in 2010, integrating its products into HP’s broader enterprise security and software portfolio. Following the separation of Hewlett-Packard into HP Inc. and Hewlett Packard Enterprise, Fortify became part of the software assets involved in HPE’s planned combination with Micro Focus. That transaction was announced in 2016 and completed in 2017, making Fortify part of Micro Focus’s portfolio of mature infrastructure and enterprise software products. OpenText acquired Micro Focus in 2023, and Fortify products consequently became part of OpenText’s cybersecurity and application security portfolio. Although the original standalone company is no longer independent, Fortify remains an active product brand under OpenText. Its market role is that of an enterprise application security platform and toolset, serving organizations that need source-code analysis, runtime application testing, vulnerability classification, and security controls integrated into software development and delivery processes.
History
Fortify Software was founded in California in 2003 with backing from Kleiner Perkins. It entered the enterprise software market at a time when security teams were increasingly seeking ways to detect vulnerabilities during software development rather than relying only on penetration testing after applications had been released. The company built its business around application security testing, including static analysis of source code and dynamic assessment of running applications. The Fortify product family included Fortify Static Code Analyzer, which analyzed application code for potentially insecure constructs, and Fortify WebInspect, which tested deployed web applications for exploitable weaknesses. These products addressed different stages of the software lifecycle: static analysis could be used by developers and security teams before deployment, while dynamic testing could assess behavior in an operating application. Fortify also created supporting software assurance capabilities, security rules, vulnerability classifications, and research intended to improve the identification and remediation of application flaws. Fortify established a security research group that maintained the Java Open Review project and the Vulncat taxonomy. The group also contributed rules for Fortify’s analysis tools and published research on topics such as JavaScript hijacking, cross-build injection, cross-site scripting prevention through observation of program output, and dynamic taint propagation. Members of the group contributed to the book "Secure Coding with Static Analysis," helping connect the company’s commercial tooling with secure-development education and research. In 2010, Hewlett-Packard acquired Fortify Software. The acquisition placed Fortify within HP’s enterprise security and software activities and expanded HP’s application security capabilities. Fortify continued to develop its product portfolio under HP ownership. In 2011, the company introduced Fortify OnDemand, a service-based offering that provided static and dynamic application testing. The launch broadened Fortify’s delivery model beyond traditional software installations and addressed customers seeking externally operated or on-demand security testing. After Hewlett-Packard separated into HP Inc. and Hewlett Packard Enterprise, Fortify became part of the HPE software assets. On September 7, 2016, HPE announced that those assets would be combined with Micro Focus. The proposed transaction reflected Micro Focus’s strategy of acquiring and managing established enterprise infrastructure and software products. The combination was completed in 2017, and Fortify became part of Micro Focus’s portfolio. OpenText acquired Micro Focus in 2023. As a result, Fortify products and related application security capabilities moved into the OpenText organization. The Fortify name therefore continued as a product and technology brand rather than as an independent company. Its continuing identity is associated with enterprise application security testing, static and dynamic analysis, software vulnerability management, and support for secure software development practices.
- 2023Fortify becomes part of OpenText
OpenText acquires Micro Focus and takes ownership of the Fortify product portfolio.
- 2017Fortify joins Micro Focus
The HPE software transaction closes, making Fortify part of Micro Focus.
- 2016HPE announces software transaction with Micro Focus
HPE announces that software assets including Fortify will be combined with Micro Focus.
- 2011Fortify OnDemand is introduced
Fortify launches an on-demand service for static and dynamic application testing.
- 2010Acquisition by Hewlett-Packard
Hewlett-Packard acquires Fortify Software and incorporates its application security capabilities into HP’s enterprise software portfolio.
- 2003Fortify Software is founded
Fortify Software is established in California with backing from Kleiner Perkins and begins developing application security testing technology.
Products and positioning
Enterprise application security and software assurance provider focused on static analysis, dynamic testing, vulnerability identification, and secure software development.
Fortify Static Code AnalyzerStatic application security testing
Fortify Static Code Analyzer is a static application security testing product designed to inspect application source code and identify patterns associated with software vulnerabilities. It supports the secure-development process by allowing organizations to find potential weaknesses before applications are deployed. The product formed one of Fortify’s core offerings and was supported by the company’s security rules, vulnerability classifications, and application security research.
Fortify WebInspectDynamic application security testing
Fortify WebInspect is a dynamic application security testing product intended to evaluate running web applications. Unlike static analysis, which examines code, dynamic testing interacts with deployed applications to identify weaknesses in their behavior and exposed interfaces. WebInspect was part of Fortify’s broader application security portfolio and complemented source-code analysis by testing software in an operational environment.
Fortify OnDemandApplication security testing service2011
Introduced in 2011, Fortify OnDemand provided static and dynamic application testing as a service. Its delivery model allowed organizations to obtain application security assessments without depending entirely on locally installed testing infrastructure. The offering extended Fortify’s portfolio toward service-based software assurance and supported customers that wanted testing capabilities integrated into development and security workflows.
Flagship businesses
- Fortify Static Code Analyzer
- Fortify WebInspect
- Fortify OnDemand
Brand decisions
- 2023OpenText acquires Micro FocusM&A
Fortify was part of Micro Focus when OpenText pursued the acquisition of the company.
What changed. OpenText acquired Micro Focus, including its Fortify products and application security capabilities.
Aftermath. Fortify continued as an OpenText-owned application security brand.
- 2016HPE announces combination with Micro FocusM&A
Following the separation of Hewlett-Packard into HP Inc. and Hewlett Packard Enterprise, Fortify was among HPE’s software assets.
What changed. HPE announced that its software assets, including Fortify, would be combined with Micro Focus.
Aftermath. The transaction was completed in 2017 and transferred Fortify into Micro Focus’s enterprise software portfolio.
- 2011Launch of Fortify OnDemandProduct launch
Application security customers were seeking testing models that could be delivered as a service.
What changed. Fortify introduced Fortify OnDemand for static and dynamic application testing.
Aftermath. The brand expanded from installed analysis tools into service-based application security testing.
- 2010Hewlett-Packard acquires Fortify SoftwareM&A
Fortify had built a portfolio around application security testing and software assurance.
What changed. Hewlett-Packard acquired Fortify Software and integrated its technology into HP’s enterprise software activities.
Aftermath. Fortify continued as part of HP’s security and software portfolio rather than operating as an independent company.
Recent events
- 2023OpenText acquires Micro Focus, including Fortify products
OpenText acquired Micro Focus, transferring ownership of the Fortify application security product portfolio to OpenText.
M&A - 2017Micro Focus completes acquisition of HPE software assets
Fortify became part of Micro Focus after the completion of the transaction involving HPE’s software business.
M&A - 2016HPE announces software combination with Micro Focus
HPE announced that its software assets, including Fortify, would be combined with Micro Focus in a transaction structured to create an independent software company.
M&A - 2011Fortify launches Fortify OnDemand
Fortify introduced Fortify OnDemand, a service providing static and dynamic application testing without requiring every customer to operate the testing infrastructure independently.
Product launch - 2010Hewlett-Packard acquires Fortify Software
Hewlett-Packard acquired Fortify Software, bringing its application security testing products into HP’s enterprise software and security portfolio.
M&A
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/fortify-software · Editorial policy · How profiles are compiled