Fortify by OpenText vs. Varonis Data Security Platform

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Fortify by OpenText
Score 9.0 out of 10
N/A
An AppSec solution formerly from Micro Focus, spanning SCA, SAST and DAST that supports the breadth and management of any application portfolio, used to secure code. Features API discovery and testing for any application, throughout the software lifecycle.N/A
Varonis Data Security Platform
Score 8.8 out of 10
N/A
Varonis offers their Data Security Platform, a modular suite of data acess and data security products providing sensitive data discovery, data access governance, unusual behavior detection, GDPR compliance support, as well as incident playbooks and cybersecurity forensic reporting.N/A
Pricing
Fortify by OpenTextVaronis Data Security Platform
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Fortify by OpenTextVaronis Data Security Platform
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoYes
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Fortify by OpenTextVaronis Data Security Platform
Best Alternatives
Fortify by OpenTextVaronis Data Security Platform
Small Businesses
GitLab
GitLab
Score 8.7 out of 10
Egnyte
Egnyte
Score 9.4 out of 10
Medium-sized Companies
Veracode
Veracode
Score 8.9 out of 10
IBM InfoSphere Information Server
IBM InfoSphere Information Server
Score 8.0 out of 10
Enterprises
Veracode
Veracode
Score 8.9 out of 10
IBM InfoSphere Information Server
IBM InfoSphere Information Server
Score 8.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Fortify by OpenTextVaronis Data Security Platform
Likelihood to Recommend
9.0
(6 ratings)
10.0
(11 ratings)
Likelihood to Renew
10.0
(1 ratings)
-
(0 ratings)
Usability
7.0
(1 ratings)
8.0
(1 ratings)
Support Rating
10.0
(1 ratings)
9.6
(3 ratings)
User Testimonials
Fortify by OpenTextVaronis Data Security Platform
Likelihood to Recommend
OpenText
It is best suited for runtime application security scanning and very useful for automation. You can seemlessly integrate with pipeline for dynamic scans. Cloud based apps can also be scanned for vulnerabilities, cross site scripting attacks. Basically all OWASP TOP 10. It is less appropriate to use if you have serverless architecture
Read full review
Varonis
The most highlighted feature of Varonis Data Security Platform is the data analyzing mechanism. It analyzes your data all the time with some special algorithms to detect any unusual activities so that it can identify any unusual behavior or users and
take necessary action to save your sensitive data. They also offer a complete dashboard solution for their customers to control across different data stores, see their current state, and any security breaches to be addressed manually.
Read full review
Pros
OpenText
  • DAST Scanning
  • API Scanning
  • Less detection of false positive
Read full review
Varonis
  • Varonis logging is very robust and captures all audit events being sent from the file servers.
  • The ability to report and alert on Active Directory account events works very well with file activity monitoring. It can show the complete picture of what an account did while being used.
  • Have a customizable dashboard is great for being able to show upper management information that only pertains to them.
Read full review
Cons
OpenText
  • Reporting could be better
  • Can be an involved setup if your organization is not using common build tools
  • Users get spammed with a lot of email updates from the service
Read full review
Varonis
  • Implementation can be challenging in some areas and can only be executed by the vendor
  • Implementation can only be executed by the vendor and additional work can be chargeable
  • Licensing can be improved upon
  • Agent based so implementation can be longer than expected
Read full review
Likelihood to Renew
OpenText
Since every firm needs to perform static code analysis on their applications, I believe Micro Focus Fortify WebInspect would work well for them (they also offer dynamic scanning, although I haven't used it myself). Different static analysis tools scan code in different ways, and Micro Focus Fortify WebInspect asks you to submit a complete build of the application along with debugging files. Depending on how your company builds its apps, this requirement may be simple or challenging.
Read full review
Varonis
No answers on this topic
Usability
OpenText
It is a cloud-based platform which can provide us a very useful and unique features like Application Assessment, Scans, Vulnerability Test, Comprehensive Reporting, Monitoring, etc. Fortify by Open Text is also outstanding in various parameters for the support and integration and it is highly adaptable in various DevOps Program where you need secure app testing with all given features.
Read full review
Varonis
Because the tool delivers on its promises and forces us to explore each functionality. Using the tool leads us to seek more knowledge and apply it to our environment, mitigating risks, reducing the attack surface, increasing the team's technical knowledge, and boosting team growth. It also demonstrates to senior management that the tool is extremely necessary for the environment.
Read full review
Support Rating
OpenText
Always receive excellent support from the vendor. No issues there.
Read full review
Varonis
Support has always been very responsive and addressed any issues we may have had in the past. Some local engineers are willing to come onsite or work over a web session to discuss creating a new rule set or look at some issues. Getting issues address has never been a problem. There was one feature we had trouble getting to function correctly, but support and local engineers were willing to work with us as much as needed to get it working correctly for our organization.
Read full review
Alternatives Considered
OpenText
Fortify Application Defender is a little more timely and upfront with a lot of their information on cyber security. we like what they provide and how they communicate with our users. I think they have a good understanding and practice in their field. they seem best suited for us and the best fit.
Read full review
Varonis
Actually, we didn't expend much time evaluating other file auditing platforms. We chose Varonis just after a serious incident and we had already heard about Varonis at a Netapp event. So it was an easy choice. We called Varonis and asked them for a PoC, that's it. The PoC became a production and it is running until this day.
Read full review
Return on Investment
OpenText
  • DevSecOps helped in reducing efforts
  • License cost was less
  • We could roll out double the count of applications with implementation of WebInspect
Read full review
Varonis
  • We have identified data classifications issues that our organization was not aware of prior to the implementation.
  • The tool does take a dedicated resource for it to be effective.
  • Varonis has improved the speed with which we can fulfill audit requests, leaving us more time for other tasks.
Read full review
ScreenShots