TELECOM

On-Premise Application Security
for Telecom

One tool to cover all layers of the product: source code, running applications, mobile builds and binary packages. Analyze rare languages (Delphi, COBOL, ABAP, etc.) and provide evidence for NIS2 and PCI DSS.
AI triage cuts up to 90% of false positives43 languages, from COBOL and ABAP to Go and TypeScriptBinary analysis for vendor packages without sourceCycloneDX SBOM from every SCA scan

Securing the world's best teams

24h

Hard deadline for the NIS2 early warning to the CSIRT

10%

Of relevant turnover: the maximum Ofcom fine

18%

Of critical dependency vulnerabilities stay critical once runtime context is applied (Datadog, State of DevSecOps 2026)

48%

Of breaches involve a third party, up 60% YoY (Verizon DBIR, 2026)

Application security testing for every telecom system

Subscriber portals

Self-service, top-ups and account management. Usually Java, JavaScript or TypeScript stacks that change every sprint.

SASTOn every commit.
DASTAgainst the running portal before it reaches production.

Source and the live portal are scored on the same severity scale.

Self-service, top-ups and account management. Usually Java, JavaScript or TypeScript stacks that change every sprint.

SASTOn every commit.
DASTAgainst the running portal before it reaches production.

Source and the live portal are scored on the same severity scale.

SAST, DAST, SCA, MAST and binary analysis in one platform

Wide language coverage

Delphi
COBOL
ABAP
PL/SQL
Perl
Pascal
Visual Basic

Static analysis of billing, provisioning and network management systems, alongside the portals, services and APIs built around them.

Scan the app subscribers actually run

Android builds (.apk or a Google Play link) and iOS builds (.ipa) are analyzed as binaries, with findings mapped to OWASP MASVS. Source code and a developer environment are not required.

Track what ships in every release

SCA maps the full dependency tree, scores supply chain health across 8 metrics, flags licensing risks and builds a CycloneDX SBOM from source code and manifests. Vulnerability data comes from NVD, GitHub, GitLab, OSV and DerScanner datasets.

Three capabilities that run inside an operator's network

  • Legacy coverage

    COBOL, PL/SQL, ABAP, Delphi. Billing and provisioning still run on them. DerScanner scores them on the same severity scale as modern stacks.

  • Binary analysis

    Vendor packages scored without source code: .dll, .exe, .apk, .ipa and .class on the same ruleset as in-house code.

  • On-prem AI

    Triage and fixes that run offline inside the operator network. DerTriage and DerCodeFix need no Internet access and can be permanently disabled.

Scale to hundreds of applications without adding headcount

One installation with separate user groups and roles per domain.

  1. Group by domain, not by tool

    Billing, portal, mobile and network teams work in their own user groups with their own roles. The platform stays one installation.

  2. Set build-blocking thresholds in the pipeline

    Limits on critical findings and minimum scores decide what blocks a build. A release train does not wait on an informational finding.

  3. Plug into the existing pipeline

    Scans run from Jenkins, GitLab CI, TeamCity and Azure DevOps Server as a build step. Results return to the same interface for every team.

Which part of telecom do you run?

Application security challenges in telecom

Challenge

Subscriber data cannot leave the network

Interconnect logic, roaming agreements and network config sit in the same repositories as application code.

Solved

Run every scan inside the network

DerScanner installs on internal servers, air-gapped networks included. Code, findings and the on-prem AI agents stay on premises.

On-premAir-gapped
Challenge

Hundreds of apps, one security team

Portals, apps, billing modules and internal tools ship on separate schedules.

Solved

Scan each release from the CI/CD already in use

Scans start from the pipeline as a build step. Findings turn into Azure Boards tasks from the DerScanner interface.

CI/CDAzure Boards
Challenge

AI-generated code nobody can trace

Teams cannot tell which commits were written by a human and which by a model.

Solved

Check every commit, whoever wrote it

SAST scans model-written code the same way as human-written code. DerCodeFix proposes fixes for vulnerabilities DerTriage confirmed.

SASTDerCodeFix
Challenge

Alert fatigue eats the queue

Most alerts never get reviewed.

Solved

Clear false positives before human review

DerTriage reviews SAST findings on premises and flags likely false positives before the security team opens the queue.

DerTriageOn-prem AI

How do telecom operators comply with NIS2, TSA and PCI DSS?

Requirement

Article 21 mandates supply chain security as part of risk management. Article 23 sets a 24-hour early warning, a 72-hour notification and a final report within one month.

What DerScanner provides

SCA across the dependency tree with supply chain health scoring. Binary analysis of supplier packages. Scan comparison that shows new and fixed vulnerabilities per application.

Artifact

CycloneDX SBOM per application and SAST report on supplier binaries.

Requirement

Article 21 mandates supply chain security as part of risk management. Article 23 sets a 24-hour early warning, a 72-hour notification and a final report within one month.

What DerScanner provides

SCA across the dependency tree with supply chain health scoring. Binary analysis of supplier packages. Scan comparison that shows new and fixed vulnerabilities per application.

Artifact

CycloneDX SBOM per application and SAST report on supplier binaries.

Frequently asked questions

Yes. Scanners, database, agents and AI modules install inside the operator network. Licensing loads from a file through the admin panel.

Run a proof of concept on one telecom system

  • Run a proof of concept on one portal or billing module, on internal servers, with results reviewed against the current toolchain.
  • Scan vendor deliverables as binaries, without source code.
  • Export SAST findings mapped to OWASP, CWE, ASVS and MASVS and a CycloneDX SBOM from SCA.

Prefer email? company@derscanner.com