Request access
Fill in the form. Account setup starts as soon as it arrives.
COMMUNITY ACCESS FOR ANDROID TEAMS
Analyze the application, clear false positives, and receive context‑aware fixes ready to apply. Ship secure code and stay ahead of compliance.
Fill in the form. Account setup starts as soon as it arrives.
We prepare the account on a cloud instance and send credentials by email.
Upload the APK, run the scan, clear the false positives, and apply the fixes.
DerScanner runs a community edition because application security testing should reach every team that ships code. The Android ecosystem absorbs over 14 million attacks a year, and a late finding costs the team that shipped the build.
A 14-day account on a DerScanner cloud instance with SAST, DerTriage, and DerCodeFix enabled for Android application scanning.
No. DerScanner analyzes the compiled package, including Java and Kotlin bytecode, so a release build is enough.
Uploads stay inside the account on the DerScanner cloud instance and are used only for the scans started from that account.
Hardcoded credentials and keys, insecure data storage, weak cryptography and unsafe inter-component communication, mapped to OWASP MASVS and CWE/SANS Top 25.
The account closes at the end of the term. A conversation with the team covers a commercial license or an on-premise deployment.
Yes. The platform deploys on customer infrastructure, including air-gapped networks, under a commercial license.
No. Community access covers Android applications. iOS scanning, including .ipa analysis, runs under a commercial license.
