I have used Fortify myself (as part of my job) to audit the source code of a very large Java
web application. Let me say that not only the tools is greatly overpriced, but it also
produced about 98% of false positives. A manual inspection of the source would have been not
only extremely less expensive, and at the same time more relevant.