Application security assessments & SSDLC
SAST, DAST, MAST, SCA and binary analysis run inside the assessment methodology already in use. The same scans plug into a customer CI/CD pipeline when the engagement builds a secure SDLC.

We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.
SAST, DAST, MAST, SCA and binary analysis run inside the assessment methodology already in use. The same scans plug into a customer CI/CD pipeline when the engagement builds a secure SDLC.
Automated analysis stands behind every review, across a customer codebase and its open-source components. Automated findings feed the write-up, whether the review is a standalone engagement or part of a larger project.
One ruleset applies to code written in-house and code delivered by a supplier, which makes two vendors comparable on the same numbers. Results feed SLAs, remediation plans and sourcing decisions.
Assessment scope comes as-is: a PHP portal, a Delphi back office, COBOL on the mainframe, Java and Python services next to them. One platform reads all of it on one severity scale, so no module leaves the report marked as out of scope.
Reports carry a custom logo and report templates, and export as PDF, HTML and CSV, plus SARIF for SAST and JSON for DAST, for a customer portal or an internal reporting system. Nothing on the cover points back to DerScanner.
Deployment runs on internal servers or on customer premises, including networks with no outbound connection. Licensing arrives as a file, so an isolated customer environment needs no activation endpoint opened.
One license covers several engagements and customer environments, including a pool of licenses allocated to on-premise installations at customer sites.
Static analysis of the systems that turn up in assessment scope: core banking, ERP, billing and records management, alongside modern services and APIs.
Binary analysis reads .dll and .exe components compiled from C and C++, iOS packages, and Java or Android bytecode. Supplier code is scored on the same severity scale as code the customer wrote.
A custom logo, report templates and a table of contents produce a document with no DerScanner branding on it. Reports export as PDF, HTML and CSV, plus SARIF for SAST and JSON for DAST, and can send by email from the interface.
SCA can generate a CycloneDX SBOM from supported source languages and tracks dependencies against CVEs from NVD, GitHub Security Advisories, GitLab and OSV. Supply chain health is scored across 8 metrics covering MavenGate, Starjacking and Typosquatting.
Hover any card to see how DerScanner handles it.
Select a framework to see which capability produces the artifact.
An early warning within 24 hours of an actively exploited vulnerability, a notification within 72 hours, and a machine-readable SBOM once the Act applies in full from 11 December 2027.
SCA that can generate a CycloneDX SBOM from supported source languages, with continuous tracking against new CVE disclosures.
CycloneDX SBOM and dependency vulnerability report.
An early warning within 24 hours of an actively exploited vulnerability, a notification within 72 hours, and a machine-readable SBOM once the Act applies in full from 11 December 2027.
SCA that can generate a CycloneDX SBOM from supported source languages, with continuous tracking against new CVE disclosures.
CycloneDX SBOM and dependency vulnerability report.
Application security and cyber risk teams that run assessments for their own customers.
Run assessments across a customer stack without a second tool for the legacy half.
Talk to us about advisory engagementsCode review, DevSecOps and compliance services delivered under a service contract.
Add code-level scanning to a catalog already sold by subscription.
Talk to us about managed servicesSmall teams whose deliverable is the report itself.
Put automated analysis behind manual review and raise the volume one consultant covers.
Talk to us about assessment workDue diligence on software arriving from suppliers, acquisitions and outsourcing.
Score a supplier deliverable without waiting for source code access.
Talk to us about vendor assessmentTeams that build and support customer systems and carry security terms in the contract.
Hand the customer a scan record with each release.
Talk to us about partner licensingYes. The platform installs inside the customer perimeter, including networks with no outbound access. Modules ship with what they need to run, and licensing loads from a file through the admin panel. Online package lookups for SCA/SBOM generation can be disabled for fully isolated environments.
Yes. Report settings hold a custom logo, report templates and a table of contents. Reports export as PDF, HTML and CSV, plus SARIF for SAST and JSON for DAST and SCA, or send by email straight from the interface.
One license covers multiple engagements and customer environments. A pool of licenses can be allocated to on-premise installations at customer sites, and the terms are settled during the pricing conversation.
Binary analysis reads .dll, .exe, .ipa, .apk, .jar and .war deliverables directly, and findings map to CWE and OWASP like any other. That covers supplier components, acquired software and published mobile applications.
43 languages in one platform, including Delphi, COBOL, ABAP, PL/SQL, Perl, Pascal and Visual Basic alongside Java, C#, Python, Go, JavaScript and TypeScript.
No. DerTriage and DerCodeFix run on the same servers as the scanners, inside the network where the platform is installed. Nothing is sent to an external provider and nothing is trained on.
Yes. The same ruleset and severity scale apply to both, and findings map to OWASP Top 10, CWE/SANS Top 25, ASVS and MASVS, which gives procurement a comparable number per supplier.
A proof of concept runs on one customer codebase, on internal servers or at the customer site. The deployment model and the licensing terms are settled in the same conversation.
Prefer email? company@derscanner.com