HomeEngagements › E-02
E-02 · 2025 · Technology · Fortify AppSec

A Fortify developer seat overclaim, cut from $4.5M to $0.9M

A technology company faced a Fortify finding that counted everyone with repository access as a licensable developer seat, including reviewers and pipeline service accounts that never ran a scan. We reduced it by 80 percent.

Open A Case →
E-02 · 2025 · Technology · Fortify AppSec
−80%
A Fortify developer seat overclaim, cut from $4.5M to $0.9M
Finding$4.5M
Settled$0.9M

The opening finding

The vendor counted every identity with repository access as a licensable Fortify developer seat, sweeping in code reviewers and continuous integration service accounts that never submitted a scan. Priced at list with back maintenance, the opening finding bore little relation to the population that actually ran static analysis.

How we defended it

We ran the same four operations we apply to every engagement, set out in full in the method.

Respond. We took over first contact within the seven day notice window, scoped under NDA, and routed all vendor communication through a single controlled channel before any self assessment data was shared.

Reconstruct. We rebuilt the entitlement position from the order forms, then assembled commit and scan evidence to map the population that actually submitted scans rather than merely held repository visibility.

Rebut. We rebutted the count line by line, showing that the licensable seat is defined by scan submission, not repository access, and that pipeline service accounts and read only reviewers are not developer seats.

Resolve. We settled on the corrected submitter count and wrote a defined seat metric into the forward agreement, separating scan submission from repository access for good.

The result

The finding fell from $4.5M to $0.9M, an 80 percent reduction, settled on the buyer's terms. The licensable population matched the developers who actually ran scans.

Related defense work

The detail of this work lives in our Fortify and AppSec audit defense. Products overlap across the estate, so the same approach informs our ArcSight SIEM security audit defense and ALA and entitlement review. The end to end sequence behind every reduction is in the complete OpenText audit defense playbook.

Your finding is a number too. We make it smaller.

This result came from a buyer side reconstruction and a line by line rebuttal. If you have received an OpenText or Micro Focus audit notice, open a case before the vendor sets the baseline.

Open A Case →