OpenText Fortify licensing is the set of License Options under which OpenText licenses its on-premises application security testing software. The governing document is the Additional License Authorizations (ALA) for Application Security software products, version 5200-2000 dated 2026-06-22, which replaced version 5200-1940 of 2025-01-20.[1] The ALA forms part of the “Applicable Agreement”, which it describes as the Micro Focus End User License Agreement, a separate master agreement, or a Quotation; the text still names Micro Focus in places, reflecting the products’ origin.[1] OpenText publishes the current ALAs alongside its EULA on its software licensing page.[3] The wider OpenText contract structure is covered in OpenText licensing.
Editions
The ALA lists nine products and seven suites. All are delivered electronically, and every one is non-production software Class 3, for both perpetual and term licences (Sonatype Fortify On Premise is term only).[1]
| Product | How it is licensed (ALA) |
|---|---|
| Fortify Static Code Analyzer (SCA) | Per Project (Build to Order), per Named Contributing Developer (Flexible Deployment), by Lines of Code, or by Scan Machine (Concurrent Scanning) |
| Software Security Center (SSC) | Every individual user licensed under Build to Order, Flexible Deployment or Lines of Code |
| WebInspect | Named User (one OS Instance), Concurrent User, Single Scan Target, Flexible Deployment Plan (one Target), Security Consultant Term |
| WebInspect Enterprise | One Instance per licence; users who configure or report on scans need SSC licences |
| Application Defender | Server per Implementation; Agents per Application Instance |
| Fortify Audit Assistant On-Premise | Per installation; at least one instance required |
| Sonatype Fortify On Premise | Per user or per application; requires SCA and SSC |
| Fortify for Managed Service Provider on Premise | By Applications and/or Scans; MSP use only, no internal use |
Source: Application Security ALA, Software Specific License Terms.[1]
The suites are catalogued as SKU rows. OpenText publishes no price for any of them.
| Suite | Contents (ALA) | Catalog |
|---|---|---|
| Security Fortify Express Edition Suite | 10 Applications; 1 WebInspect Named User | Security Fortify Express Edition Suite |
| Security Fortify Premium Edition Suite | 10 Applications; 5 Scanning Users; SCA Static Engine; Secure Coding Plug-ins; Audit Workbench; SSC | Security Fortify Premium Edition Suite |
| Security Fortify Ultimate Edition Suite | Premium contents plus Unlimited Dynamic Applications and WebInspect Enterprise | Security Fortify Ultimate Edition Suite |
| Software Security Center Build to Order Starter Edition | 1 SSC Server; 1 Power User; 1 Scanning Machine; 30 Projects | Security Software Security Center Starter Edition |
| Software Security Center Build to Order Starter Edition w/o SSC Server | As above without the SSC Server | Security Software Security Center Starter Edition without SSC Server |
| WebInspect Enterprise Build to Order Starter Edition Suite | 1 SSC Server; 1 WebInspect Enterprise OS Instance; 1 Sensor; 1 WebInspect Named User; 5 SSC Regular Users | Security WebInspect Enterprise Build to Order Starter Edition Suite |
Source: Application Security ALA, Application Security Suite offerings.[1]
Products bought after 2026-06-29 no longer include the right to use COBOL Enterprise Analyzer for translating COBOL applications.[1]
Metrics
The ALA defines its own units, separate from the OpenText License Model Schedule:[1]
- Project. “a unique code base analyzed by Security Fortify Static Code Analyzer”.
- Power User and Regular User. Named users of SSC and SCA; a Power User can scan and view results for all Projects, a Regular User only for Projects they have worked on.
- Named Contributing Developer. Anyone who committed code to the scanned Projects in the past 90 days.
- Lines of Code. The aggregate source lines, before compilation, in all Projects to be scanned, counted “by an industry standard method”.
- Fortify Scan Machine and Fortify User. The two units of the Concurrent Scanning License Model.
- Target. “a unique logical computer system being scanned”, usually one fully qualified domain name; a web application that also exposes mobile end-points is two Targets.
Counting / floors
Build to Order
Each unique code base scanned by SCA is a Project, however the scan is launched, and “A separate license for each Project is required. Project licenses cannot be reused or reassigned.”[1] Catalog: Fortify Static Code Analyzer: one licence per Project; Project licences cannot be reused or reassigned. On the SSC server, a Regular User or Power User licence is required for any individual who uses it for any purpose, including only viewing results and reports.[1] Catalog: Fortify Software Security Center: every individual using the server must be licensed under Build to Order, Flexible Deployment or Lines of Code.
Flexible Deployment Plan
The plan includes unlimited use of SSC, SCA, Audit Workbench and IDE plug-ins, but only for code written by licensed Named Contributing Developers. It “is not based on the number of people using the software”. At least one Named Contributing Developer licence is required per Project, and code from developers outside the licensed number may not be scanned.[1] Catalog: Fortify Flexible Deployment Plan: Named Contributing Developers counted over a rolling 90 days, at least one per Project. The count is the number of committers in a rolling 90-day window, so it has to be read from source control history rather than from a directory of Fortify users.
Lines of Code Plan
Unlimited users and machines may scan the authorized Lines of Code. The licence quantity is the total source lines across all Projects to be scanned.[1] In Flexible Deployment and Lines of Code plans, any authorized individual may use SSC, but only for licensed Projects.[1]
Concurrent Scanning License Model
This model counts active scans instead of installations. SCA and WebInspect may be installed on unlimited machines; each running scan or translation needs a Fortify Scan Machine licence, so “A machine running two (2) scans requires two (2) Fortify Scan Machine licenses.” Anyone using SSC or Fortify tooling, including Audit Workbench, IDE plug-ins, Security Assistant and the Packaging Utility, needs a Fortify User licence.[1]
The model has a floor of two Scan Machines and one Fortify User, or one Dynamic Only Scan Machine and one Fortify User, per customer, and “No mixing of license models is allowed.”[1] Catalog: Fortify Concurrent Scanning: minimum two Scan Machines and one Fortify User per customer; no mixing of models.
WebInspect
A WebInspect Named User licence is for one OS Instance, with no limit on scans or Targets. Concurrent User licences require an installed and active License and Infrastructure Manager. A Single Scan Target licence scans one IP address without limit, may be installed on up to five logical systems, and allows two IP address changes in 12 months. A Flexible Deployment Plan licence scans one Target from any number of systems.[1] Catalog: WebInspect Single Scan Target: one IP address, up to five logical systems, two IP changes per 12 months.
For WebInspect Enterprise, everyone who configures, manages, runs, audits, reviews or reports on scans must hold an SSC user licence; users who only log in to request scans do not.[1]
Older add-ons
Fortify Add-on Applications and Static or Dynamic Engines bought before 2015-05-01 were licensed by Application and Engine; all Fortify add-ons require a licence for one of the Edition suites.[1]
Virtualization & partitioning
The ALA’s OS Instance definition counts every virtual machine, container, guest and zone as a separate OS Instance, which matters for WebInspect Named User licences.[1] Under the Concurrent Scanning model, a machine “is considered to be anything used for physical or virtual scanning (including a container)”, but only scanning machines are counted.[1]
Cloud / BYOL
The ALA prohibits installing or using the software “on any third party or shared (hosted) server without explicit consent from the third party”, and limits scanning to software the customer owns, has a licence to use, or has the owner’s explicit consent to scan.[1] Catalog: Fortify and WebInspect: scan only owned or licensed software; no installation on third-party or shared hosted servers without consent. Scanning on behalf of other companies is reserved for the Managed Service Provider and Security Consultant offerings, which require a Managed Service Provider Agreement and cannot be used internally.[1] No public-cloud BYOL terms are published in the ALA.
Programs
- Term LTU. A licence “valid for a specific period of time such as One Month (1 M), One Year (1 Y)”; term LTUs are not perpetual.[1] See Term License to Use (Term LTU) and Term Support.
- Non-production. All Application Security products are Class 3.[1] Class 3 products get no free non-production licences under the Non-Production Licensing Guide.[2] See Non-Production Licensing (Classes 1-4).
- Benchmarks. Publishing benchmark results or detailed comparisons with other products needs prior written consent, where the law allows the restriction.[1]
Out of scope
- Fortify on Demand, Fortify Hosted and other SaaS offerings, which are governed by Service Descriptions.
- Prices and part numbers, which OpenText does not publish.
- Application Defender SaaS and the Sonatype SaaS components.
- Earlier ALA versions, including 5200-1940 (2025-01-20).