Home
Products
Detect Vulnerabilities
SCA in Development
The Fortify Source Code Analyzer (SCA) examines every line of code and every program path to identify hundreds of different types of potentially exploitable vulnerabilities early in the development lifecycle, when they're cheapest to fix.
SCA is comprehensive in the vulnerabilities it finds and complete in what it analyzes. Its analyzers and patented X-Tier™ Dataflow analysis (patent #7207065) detect a breadth of issues at a depth unmatched by other technologies. Its analyzers are guided by the largest and most comprehensive set of secure coding rules, which are continually updated by the experts in the Fortify Security Research Group. SCA identifies more than 200 vulnerability categories
The sophisticated engines and precise secure coding rules in SCA deliver ranked and categorized issues with a very low false positive rate. In addition, because no two applications have the same risk profile or are built the same way, SCA enables organizations to further tune the analysis to accommodate a particular application, component or Web service.
SCA is designed to fit into your organization. It can scale from daily builds to full-scale audits of millions of lines of code and supports a wide array of languages, platforms, build environments and integrated development environments (IDEs). Its level of analysis can be tuned for individuals or groups with different objectives. For applications that require unique rules, SCA provides an easy-to-use Rules Builder for customized analysis.
Contact me about products from Fortify Software
"We strongly believe that Fortify's holistic approach to application security - implementing security during all stages of development, rather than after the fact - proactively helps eliminate business risk and truly safeguards our enterprise against today's ever-changing security threats."
Craig Shumard, CISO, CIGNA
"We looked into a number of tools and tested them against our source base. The vast majority of them could not handle the size, scope and nature of our applications. Of all the products we tested, Fortify came closest to our technical requirements."
Oracle
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"Auditing at the source code level is the best way to protect applications early in the SDL. Fortify SCA will give us the opportunity to fix vulnerabilities before we push out new versions of our applications. In our view, the alternative is a security breach, and that is simply unacceptable."
Mark Crockett, Vice President of Technology and CTO of Informa Investment Scorecard
"Fortify is one of the largest SAST vendors, with strong innovation as well as execution capabilities. It has expanded its technologies beyond SAST into a broader spectrum of application security disciplines that supplement its core SAST capabilities."
Gartner MQ
"We are very pleased with our decision to integrate Fortify products into our source code review and applications security audit processes"
Rick Dakin, QSA and Cofounder of Coalfire