FINANCIAL SERVICES

One tool to cover all layers of the product: source code, running applications, mobile builds and binary packages. Analyze rare languages (COBOL, ABAP, Delphi, etc.) and provide evidence for DORA and PCI DSS.
  • On-prem AI triage cuts up to 90% of false positives
  • 43 languages, from COBOL and ABAP to Go and TypeScript
  • Air-gapped: a license file, zero outbound connections
  • SAST findings mapped to OWASP, CWE, ASVS and MASVS, CycloneDX SBOM from SCA

Securing the world's best teams

43

languages, from COBOL to TypeScript

Up to 90%

of false positives cut by AI triage

5

analysis types, one severity scale

0

bytes leave the network

SAST, DAST, SCA, MAST and binary analysis in one platform

Wide language coverage

Delphi
COBOL
ABAP
PL/SQL
Perl
Pascal
Visual Basic

Static analysis of the systems a bank actually runs: core banking, card processing, lending and back office, alongside modern services and APIs. All five engines share one installation and one severity scale across the whole estate.

90%

Cut the queue by up to 90%

DerTriage verifies SAST detections and cuts up to 90% of false positives. DerCodeFix generates context-aware fixes for the vulnerable snippet. Both run offline inside the perimeter.

Assess supplier code without source

Binary analysis scores vendor deliverables on the same ruleset as in-house code.

.dll.exe.apk.ipa.class

Run every scan inside the network

Licensing loads from a file. No code and no findings reach a vendor endpoint.

On-premisePrivate cloudAir-gapped

Track every component in every release

CycloneDX SBOM per scan. Supply chain health scored across 8 metrics.

CVEs from
NVDGitHubGitLabOSV

Where scanning sits inside the delivery pipeline

COMMIT

A finding fixed at commit costs minutes of developer time: issues are caught on the branch, before they accumulate into release debt.

  • SAST runs on every push to the selected branches.
  • Run scans on each commit to prevent breaches.
  • Results land in the DerScanner interface while the change is still on the branch.

BUILD

The build gate is where a vulnerable artifact stops being invisible: the assembled release candidate is checked as a whole, without a single byte leaving the perimeter.

  • Jenkins, TeamCity and Azure DevOps Server run SAST as a build step, GitLab CI runs SAST, DAST and SCA. The build stops when critical findings are found.
  • The scan runs on internal servers. No data crosses the perimeter.

PRE-RELEASE

The final checkpoint before users: web and mobile are verified together, so a release never ships with an untested channel.

  • DAST runs against the staging environment. MAST scans the mobile build.
  • Both channels are covered before the release ships to app stores or production.

IN PRODUCTION

Release is not the end of coverage: shipped apps and vendor binaries stay scored, so nothing in production turns into a blind spot.

  • Published Android builds are scanned from the APK or the Google Play link.
  • Vendor deliverables arrive as binaries and are scored with the same ruleset as in-house code.

Four constraints that are hard to handle at once

Challenge

Source code cannot leave the perimeter

Code residency is written into contracts and internal policy. SaaS scanners live in the vendor's cloud, and even the most secure cloud is still outside the bank.

Solved

Run every scan inside the perimeter

Scanners, database, agents and AI modules install on internal servers, air-gapped included. Licensing loads from a file.

On-premAir-gappedOn-prem AI agents
Challenge

Core systems predate the toolchain

Card processing, lending and back office still run on COBOL, ABAP, Delphi and PL/SQL — the systems most sensitive to disruption and most in need of protection.

Solved

43 languages on one severity scale

Legacy stacks are analyzed alongside Java, Go and TypeScript. One severity scale across the whole estate.

SASTLegacy coverage
Challenge

Supplier code arrives without source

Vendor and integrator deliverables still need a security score on the same scale as in-house development.

Solved

Scan supplier builds without source

Binary analysis reads .dll, .exe, .apk, .ipa, .jar and .war packages and scores them on the same ruleset.

Binary analysisSAST
Challenge

Audit evidence is assembled by hand

Supervisors ask what was scanned, when, and what happened to each finding. The answer is pieced together for every audit.

Solved

Export audit evidence from scan history

Event logs, comparison reports and OWASP / CWE mapping export from scan history without manual assembly.

Event logScans ComparisonReports

How do banks comply with DORA, PCI DSS and ISO 27001?

Requirement

A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.

What DerScanner provides

SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every SAST finding carries an event log of the actions taken on it. The same ruleset applies to supplier code as to in-house code.

Artifact

SAST report with scan comparison and SCA report with the component list.

Requirement

A major incident must be reported within 4 hours of classification, and no later than 24 hours from awareness. An intermediate report follows within 72 hours. ICT risk management extends to third-party providers.

What DerScanner provides

SAST, DAST, SCA and MAST from an installation inside the bank perimeter. Every SAST finding carries an event log of the actions taken on it. The same ruleset applies to supplier code as to in-house code.

Artifact

SAST report with scan comparison and SCA report with the component list.

Teams already shipping with DerScanner

When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the capabilities of the product. DerScanner addresses our main challenge of checking the health of our product's code.

DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.

We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.

Frequently asked questions

Yes. Every module installs on internal servers, including networks with no outbound access. Licensing loads from a file through the admin panel.

Run a proof of concept on bank infrastructure

  • Run a proof of concept on one system - core banking, mobile app or vendor binary.
  • Install on internal servers, on-premise or fully air-gapped.
  • Export audit evidence from SAST and a CycloneDX SBOM from SCA.

Prefer email? company@derscanner.com