Source code cannot leave the perimeter
Code residency is written into contracts and internal policy. SaaS scanners live in the vendor's cloud — even the most secure cloud is still outside the bank.
languages, from COBOL to TypeScript
false positives cut by AI triage
engines, one severity scale
bytes leave the network
Static analysis of the systems a bank actually runs: core banking, card processing, lending and back office, alongside modern services and APIs. All five engines share one installation and one severity scale across the whole estate.
DerTriage verifies SAST detections and cuts up to 90% of false positives. DerCodeFix generates context-aware fixes for the vulnerable snippet. Both run offline inside the perimeter.
Binary analysis scores vendor deliverables on the same ruleset as in-house code.
Licensing loads from a file. No code and no findings reach a vendor endpoint.
CycloneDX SBOM per scan. Supply chain health scored across 8 metrics.
COMMIT
A finding fixed at commit costs minutes of developer time: issues are caught on the branch, before they accumulate into release debt.
BUILD
The build gate is where a vulnerable artifact stops being invisible: the assembled release candidate is checked as a whole, without a single byte leaving the perimeter.
PRE-RELEASE
The final checkpoint before users: web and mobile are verified together, so a release never ships with an untested channel.
IN PRODUCTION
Release is not the end of coverage: shipped apps and vendor binaries stay scored, so nothing in production turns into a blind spot.
Code residency is written into contracts and internal policy. SaaS scanners live in the vendor's cloud — even the most secure cloud is still outside the bank.
Scanners, database, agents and AI modules install on internal servers, air-gapped included. Licensing loads from a file.
Card processing, lending and back office still run on COBOL, ABAP, Delphi and PL/SQL — the systems that handle the most money.
Legacy stacks are analyzed alongside Java, Go and TypeScript. One severity scale across the whole estate.
Vendor and integrator deliverables still need a security score on the same scale as in-house development.
Binary analysis reads .dll, .exe, .apk, .ipa, .jar and .war packages and scores them on the same ruleset.
Supervisors ask what was scanned, when, and what happened to each finding. The answer is pieced together for every audit.
Event logs, comparison reports and OWASP / CWE mapping export from scan history — no manual assembly.
A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.
SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every finding carries a timestamped event log. The same ruleset applies to supplier code as to in-house code.
SAST Verification Report, Finding Event Log and Third-Party Components Report.
A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.
SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every finding carries a timestamped event log. The same ruleset applies to supplier code as to in-house code.
SAST Verification Report, Finding Event Log and Third-Party Components Report.
When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the capabilities of the product. DerScanner addresses our main challenge of checking the health of our product's code.
DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.
We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.
Yes. Every module installs on internal servers, including networks with no outbound access. Each module arrives with its own runtime environment, so an isolated server downloads nothing during setup. Licensing loads from a file through the admin panel.
Reports export as PDF, HTML, CSV or JSON. A CycloneDX SBOM is generated per scan. Every finding carries a timestamped event log with its full status history.
43 languages in one platform, including COBOL, ABAP, Delphi, PL/SQL, Perl, Pascal and Visual Basic alongside Java, C#, Python, Go, JavaScript and TypeScript.
Yes. MAST scans the published build from its store link. Binary analysis reads the .ipa or .apk directly when the build is supplied as a file.
The same ruleset and severity scale apply to supplier code. Binary analysis reads .dll, .exe, .ipa, .apk, .jar and .war deliverables when source access is not part of the contract.
No. DerTriage and DerCodeFix run on the same servers as the scanners, inside the network where the platform is installed. Nothing is sent to an external provider and nothing is trained on your code.
Scans run from Jenkins, GitLab and GitHub jobs and return results into the pipeline. A release stage reads findings without opening a separate console.
Hybrid SAST and SCA analysis builds a call graph from application code through transitive dependencies and marks whether a vulnerable function is reachable, for JavaScript, TypeScript, Python, C# and Java. DerTriage runs the first pass on the same servers as the scanners.
The platform does not label code by author. Every commit goes through the same rules and the same severity scale. This matters when a release mixes hand-written and generated code and nobody can trace which is which.
A proof of concept runs on one system, on bank infrastructure, with the scope and deployment model agreed in the same conversation. You review the results against what your current tools find.
Prefer email? company@derscanner.com