FINANCIAL SERVICES

One tool to cover all layers of the product: source code, running applications, mobile builds and binary packages. Analyze rare languages (COBOL, ABAP, Delphi, etc.) and provide evidence for DORA and PCI DSS.
  • On-prem AI triage cuts false positive noise by 90%
  • 43 languages, from COBOL and ABAP to Go and TypeScript
  • Air-gapped: a license file, zero outbound connections
  • SAST findings mapped to OWASP, CWE, ASVS and MASVS, CycloneDX SBOM from SCA

Securing the world's best teams

43

languages, from COBOL to TypeScript

90%

false positives cut by AI triage

5

engines, one severity scale

0

bytes leave the network

SAST, DAST, SCA, MAST and binary analysis in one platform

Wide language coverage

Delphi
COBOL
ABAP
PL/SQL
Perl
Pascal
Visual Basic

Static analysis of the systems a bank actually runs: core banking, card processing, lending and back office, alongside modern services and APIs. All five engines share one installation and one severity scale across the whole estate.

90%

Cut the queue by 90%

DerTriage verifies SAST detections and cuts up to 90% of false positives. DerCodeFix generates context-aware fixes for the vulnerable snippet. Both run offline inside the perimeter.

Assess supplier code without source

Binary analysis scores vendor deliverables on the same ruleset as in-house code.

.dll.exe.apk.ipa.jar.war

Run every scan inside the network

Licensing loads from a file. No code and no findings reach a vendor endpoint.

On-premisePrivate cloudAir-gapped

Track every component in every release

CycloneDX SBOM per scan. Supply chain health scored across 8 metrics.

CVEs from
NVDGitHubGitLabOSV

Where scanning sits inside the delivery pipeline

COMMIT

A finding fixed at commit costs minutes of developer time: issues are caught on the branch, before they accumulate into release debt.

  • SAST runs on every push to the selected branches.
  • Run scans on each commit to prevent breaches.
  • Developers see results before the code review starts.

BUILD

The build gate is where a vulnerable artifact stops being invisible: the assembled release candidate is checked as a whole, without a single byte leaving the perimeter.

  • Jenkins, GitLab CI, TeamCity or Azure DevOps run SAST, DAST and SCA as build steps and stops the build when critical findings are found.
  • The scan runs on internal servers. No data crosses the perimeter.

PRE-RELEASE

The final checkpoint before users: web and mobile are verified together, so a release never ships with an untested channel.

  • DAST runs against the staging environment. MAST scans the mobile build.
  • Both channels are covered before the release ships to app stores or production.

IN PRODUCTION

Release is not the end of coverage: shipped apps and vendor binaries stay scored, so nothing in production turns into a blind spot.

  • Published Android builds are scanned from both APK file or the Google Play link.
  • Vendor deliverables arrive as binaries and are scored with the same ruleset as in-house code.

Four constraints that are hard to handle at once

Challenge

Source code cannot leave the perimeter

Code residency is written into contracts and internal policy. SaaS scanners live in the vendor's cloud — even the most secure cloud is still outside the bank.

Solved

Run every scan inside the perimeter

Scanners, database, agents and AI modules install on internal servers, air-gapped included. Licensing loads from a file.

On-premAir-gappedOn-prem AI agents
Challenge

Core systems predate the toolchain

Card processing, lending and back office still run on COBOL, ABAP, Delphi and PL/SQL — the systems that handle the most money.

Solved

43 languages on one severity scale

Legacy stacks are analyzed alongside Java, Go and TypeScript. One severity scale across the whole estate.

SASTLegacy coverage
Challenge

Supplier code arrives without source

Vendor and integrator deliverables still need a security score on the same scale as in-house development.

Solved

Scan supplier builds without source

Binary analysis reads .dll, .exe, .apk, .ipa, .jar and .war packages and scores them on the same ruleset.

Binary analysisSAST
Challenge

Audit evidence is assembled by hand

Supervisors ask what was scanned, when, and what happened to each finding. The answer is pieced together for every audit.

Solved

Export audit evidence from scan history

Event logs, comparison reports and OWASP / CWE mapping export from scan history — no manual assembly.

Event logScans ComparisonReports

How do banks comply with DORA, PCI DSS and ISO 27001?

Requirement

A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.

What DerScanner provides

SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every finding carries a timestamped event log. The same ruleset applies to supplier code as to in-house code.

Artifact

SAST Verification Report, Finding Event Log and Third-Party Components Report.

Requirement

A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.

What DerScanner provides

SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every finding carries a timestamped event log. The same ruleset applies to supplier code as to in-house code.

Artifact

SAST Verification Report, Finding Event Log and Third-Party Components Report.

Teams already shipping with DerScanner

When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the capabilities of the product. DerScanner addresses our main challenge of checking the health of our product's code.

DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.

We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.

Frequently asked questions

Yes. Every module installs on internal servers, including networks with no outbound access. Each module arrives with its own runtime environment, so an isolated server downloads nothing during setup. Licensing loads from a file through the admin panel.

Run a proof of concept on bank infrastructure

  • Run a proof of concept on one system - core banking, mobile app or vendor binary.
  • Install on internal servers, on-premise or fully air-gapped.
  • Export audit evidence from SAST and a CycloneDX SBOM from SCA.

Prefer email? company@derscanner.com