Home / Solutions / On-premise / Air-gapped
ON-PREMISE / AIR-GAPPED

A scanner hosted in a vendor cloud takes in source code, credentials and internal hostnames, and becomes one more place all of it can leak from. DerScanner installs on your premises and runs there in full, AI agents included.
Zero outbound connectionsLicense by file, no activation serverAI modules run locally
DerScanner on-premise dashboard: scanning inside the network perimeter
0%

Of breaches involve the supply chain, up 60% year over year

Verizon DBIR 2026

$4.99M

Global average cost of a data breach, a record high

IBM Cost of a Data Breach Report 2026

0

Outbound connections required to run a full scan

0

Languages analyzed inside the perimeter

Run scans without a single outbound connection

01

Scan source directly from Git

Analysis modules start on servers inside the network, pull the repository over an internal Git connection and write results to a database on the same network. The code never passes through a vendor endpoint at any stage of the scan.

02

Run the AI agents locally

DerTriage filters false positives and DerCodeFix writes fix suggestions, both on the same servers as the scanners and with no internet access needed. An AI policy review stops being a reason to switch the features off.

03

License without an activation server

A license arrives as a file and loads through the admin panel. There is no activation endpoint for a firewall team to whitelist, and a certificate authority change cannot take the platform offline.

04

Send the audit trail to the internal SIEM

Every module writes event logs to the file system of the server it runs on, and security events forward over syslog to an internal collector. The audit trail lands where the SOC already looks.

Every module runs inside the network

Wide language coverage

Delphi
COBOL
ABAP
PL/SQL
Perl
Pascal
Visual Basic

Static analysis of the systems that rarely leave the internal network in the first place: core banking, ERP, plant control and records management.

Scale scanning inside the same network

The main module holds the interface, the API and the data on one server. SAST, DAST and SCA install next to it or on their own machines, and each one spreads across several servers once scans start queuing.

Install on a host with no internet access

Each module arrives with the environment it needs to run. Setup and updates happen from that package, so an isolated server never reaches out to an external repository.

Plug into the CI/CD and IDEs already in use

DerScanner connects to Jenkins, TeamCity and Azure DevOps, to Eclipse, IntelliJ IDEA and Visual Studio, and to Jira and SonarQube. A command line client covers whatever the list misses, and all of it stays inside the network.

Log in with corporate accounts

LDAP connects DerScanner to the corporate directory, so accounts follow the joiner and leaver process already in place. Access is scoped per project, with read-only roles for auditors.

Everything runs locally

SAST

Static analysis across 43 languages, from legacy modules to modern services, running on changed files at every commit.

DAST

Runtime testing of web applications and their APIs against authentication, session handling and injection flaws.

SCA

Open-source dependencies resolved to full depth and checked against CVEs, with a CycloneDX SBOM generated on every scan.

MAST

iOS and Android applications, source and compiled package, checked for insecure storage, weak crypto and permission scope.

Binary analysis

.dll, .exe, .ipa, .apk, .jar and .war deliverables scanned directly with no source code, and findings mapped to CWE and OWASP like any other.

DerTriage

False positives filtered against real exploitability data, so the queue reaching developers holds what actually matters.

DerCodeFix

Fix suggestions written inline against the surrounding code, so the developer applies the change without leaving the file.

Application compliance

Findings mapped to OWASP and CWE and exported as the evidence a review asks for, in PDF, HTML or CSV.

Three reasons a scanner stays inside the network

Hover any card to see how DerScanner handles it.

What regulators ask for on-premises deployment

Select a framework to see what it requires and what DerScanner produces for it.

Requirement

Security of processing under Art. 32, and conditions on transferring personal data outside the EEA under Art. 44 onward.

What DerScanner provides

A deployment that holds source code and scan data inside the existing infrastructure, which removes the transfer from scope.

Artifact

Deployment architecture description.

Requirement

Security of processing under Art. 32, and conditions on transferring personal data outside the EEA under Art. 44 onward.

What DerScanner provides

A deployment that holds source code and scan data inside the existing infrastructure, which removes the transfer from scope.

Artifact

Deployment architecture description.

Download sample compliance reports

Where an install on your premises is the only option

Government and defense

Classified and CUI networks carry no route to the public internet by design.

Scan classified code without moving it to a network that has one.

Talk to us about classified networks

Banks and financial institutions

A regulator, an internal audit function and a third-party risk register all ask where the code goes.

Answer the ICT third-party question with a deployment diagram.

Talk to us about financial compliance

Critical infrastructure and OT

Segmented industrial zones take new software through a controlled conduit, and nothing dials out.

Deploy into a segment without opening a conduit for the scanner.

Talk to us about industrial networks

Healthcare and pharma

ePHI, clinical systems and GxP-validated environments sit under data residency rules.

Scan ePHI-handling applications without moving data off site.

Talk to us about clinical systems

Manufacturing and automotive

Joint development agreements decide where pre-production source code may travel.

Answer a confidentiality clause with the deployment diagram.

Talk to us about supplier code

Teams already shipping with DerScanner

Who verified DerScanner

When looking for the scanner to build our secure development process on, we evaluated the capabilities of global leading vendors. We were surprised with the very convenient licensing model along with the impressive capabilities of the product. DerScanner is an optimal solution to our main challenge of checking the health of our product's code.

DerScanner discovered potential weaknesses that would have been difficult or even impossible to find, even in long-standing, mature code. I definitely recommend DerScanner if you are serious about the security of your code and the apps you create.

We use DerScanner to support our secure code review and SAST services. Its broad language support, reliable static analysis, and actionable findings help our consultants deliver consistent, high-quality security assessments.

Frequently asked questions

A scan produces nothing that leaves it. Analysis modules run on internal servers, results write to a database on the same network, and the AI agents execute on the same infrastructure. Licensing arrives as a file through the admin panel, so there is no activation server for a firewall team to whitelist.

Deploy safely, on your premises

  • Run a proof of concept on one codebase inside the restricted environment.
  • Install on your premises or fully air-gapped, with no outbound connection at any point.
  • Request the vendor security assessment materials before the review starts.

Prefer email? company@derscanner.com