Why On-Premise AST Stopped Being Optional for Regulated Industries

For most of the last decade, cloud deployment was the default, on-premise was the legacy option, and air-gapped was for the paranoid. 2026 has been reversing that ranking, and the reversal is driven by regulatory events.

Content

Make Your Applications Secure Today

Sign up for a personalized demo to see how DerScanner can meet your Application Security needs

Application security vendors turned out to be excellent supply chain targets because their tooling sits inside CI/CD with elevated trust.

The clearest case study is the TeamPCP campaign against Checkmarx. It started in March, when the compromise of Aqua Security's Trivy GitHub Action leaked credentials that, by Checkmarx's own account, gave attackers access to its GitHub environment, with data exfiltration confirmed on March 30. In April, Trend Micro documented TeamPCP overwriting the official KICS images on Docker Hub, poisoning two VS Code extensions, and modifying a GitHub Actions workflow in a coordinated 83-minute strike; stolen npm tokens from that wave briefly compromised the Bitwarden CLI package downstream. 

In May, the group backdoored the Checkmarx Jenkins plugin using credentials retained from the earlier breaches, the third distinct compromise of the vendor's distribution channels in six weeks.

A security vendor's update channel is a privileged path into thousands of customer pipelines, and attackers have internalized that faster than procurement processes have. The agentjacking research against Sentry's MCP integration made the same point from another angle in June: the integrations vendors ship are an attack surface, including the AI-accessible ones.

 

Three forcing functions

The vendor connection itself
Every SaaS AST platform requires a standing channel between the customer's code and the vendor's infrastructure: upload APIs, CI plugins, IDE extensions, and now MCP servers and AI assistants. Each is a component the customer cannot audit and a compromise path the customer cannot close. The TeamPCP chain demonstrated the failure mode end to end, from one stolen token to poisoned artifacts in customer pipelines.

 

What leaves the building
Cloud SAST means source code, or, at minimum, rich intermediate representations of it, leaves the perimeter, along with the findings data that amounts to a map of known weaknesses. For a bank or a defense contractor, the vulnerability report is arguably more sensitive than the code. The Checkmarx incident included confirmed data exfiltration from the vendor side, which converts this from a theoretical objection into a documented one.

 

Regulation pressure
The EU's NIS2 directive makes supply chain security an explicit management responsibility for essential and important entities, including the security of relationships with direct suppliers, like AST scanners. DORA, applying to EU financial entities since January 2025, requires managed ICT third-party risk with exit strategies, which auditors increasingly read as: know where the code goes and be able to stop sending it. Outside the EU, data-localization regimes across the CIS, Southeast Asia, and the Gulf add a blunter constraint: in some sectors source code and findings may not lawfully cross the border at all. In each case the regulation connects to a concrete question a cloud deployment struggles to answer clearly: whose infrastructure holds the code, the findings and the credentials, and under which jurisdiction.

On-premise stopped being a conservative preference and became the path of least compliance resistance. The burden of proof flipped sides.

 

When cloud is the right call

Cloud AST remains a sensible default for teams whose code already lives in public SaaS repositories, whose product is itself cloud-native, and who face no sector-specific data residency rules. It wins on time to first scan, removes patching and capacity from the customer's plate, and for a startup shipping a web application, standing up scanning servers is effort spent in the wrong place. The argument here concerns regulated estates: banking cores, government registries, healthcare platforms, critical infrastructure. For that category, the events of 2026 moved the calculation.

 

What on-premise looks like

The label needs scrutiny, because some products sold as on-premise still require connection for licensing, rule updates, or AI features that call a hosted model through an API. Tools that advertise AI capabilities often work exactly that way, which reintroduces the outbound channel the deployment was meant to eliminate.

DerScanner installs fully within the customer's infrastructure, with SAST, SCA, DAST, and binary analysis modules deployed as services on the customer's hosts, and supports air-gapped operation with no outbound Internet access, including the AI-powered triage and fix generation agents.

The industry spent years framing on-premise as technical debt. 2026 reframed it as risk management: every external connection in the security toolchain is now a documented attack path, and regulators have started asking the questions attackers answered first.

 

Teams drawing up requirements for their next AST evaluation can pressure-test the air-gapped claim directly, a demo against a disconnected environment settles it faster than a datasheet, and the SAST overview documents which capabilities run locally.

Loading blogs...
Get Started

Ready to Reduce Technical Debt and
Improve Security?

Clean code. Fewer risks. Stronger software

dashboard