TELECOM

On-Premise Application Security
for Telecom

One tool to cover all layers of the product: source code, running applications, mobile builds and binary packages. Analyze rare languages (Delphi, COBOL, ABAP, etc) and provide evidence for NIS2 and PCI DSS.
AI triage cuts false positives by 90%43 languages, from COBOL and PL/SQL to Go and TypeScriptBinary analysis for vendor packages without sourceCycloneDX SBOM generated on every scan

Securing the world's best teams

24h

Hard deadline for the NIS2 early warning to the CSIRT

10%

Of relevant turnover — the maximum Ofcom fine

18%

Of critical dependency vulnerabilities stay critical with runtime context (Datadog, 2026)

48%

Of breaches involve a third party, up 60% YoY (Verizon DBIR, 2026)

Application security testing for every telecom system

Subscriber portals

Self-service, top-ups and account management. Usually Java, JavaScript or TypeScript stacks that change every sprint.

SASTOn every commit.
DASTAgainst the running portal before it reaches production.

Source and the live portal are scored on the same severity scale.

Self-service, top-ups and account management. Usually Java, JavaScript or TypeScript stacks that change every sprint.

SASTOn every commit.
DASTAgainst the running portal before it reaches production.

Source and the live portal are scored on the same severity scale.

SAST, DAST, SCA, MAST and binary analysis in one platform

Wide language coverage

Delphi
COBOL
ABAP
PL/SQL
Perl
Pascal
Visual Basic

Static analysis of billing, provisioning and network management systems, alongside the portals, services and APIs built around them.

Scan the app subscribers actually run

The published Android or iOS build is analyzed as a binary against OWASP MASVS. Source code and a developer environment are not required.

Track what ships in every release

SCA maps the full dependency tree, scores supply chain health across 8 metrics, flags licensing risks and generates a CycloneDX SBOM per scan. Vulnerability data comes from NVD, GitHub, GitLab, OSV and DerScanner datasets.

Three capabilities that run inside an operator's network

  • Legacy coverage

    COBOL, PL/SQL, ABAP, Delphi. Billing and provisioning still run on them. DerScanner scores them on the same severity scale as modern stacks.

  • Binary analysis

    Vendor packages scored without source code: .dll, .exe, .apk, .ipa and .class on the same ruleset as in-house code.

  • On-prem AI

    Triage and fixes that run offline inside your network. DerTriage and DerCodeFix need no Internet access and can be permanently disabled.

Scale to hundreds of applications without adding headcount

One installation with separate reporting, policies and access rights per domain.

  1. Group by domain, not by tool

    Billing, portals, mobile and network tools sit in separate project groups with their own access rights and policies. The platform stays one installation.

  2. Set build-blocking thresholds in the pipeline

    Limits on critical findings and minimum scores decide what blocks a build. A release train does not wait on an informational finding.

  3. Plug into the existing pipeline

    Scans run from Jenkins, GitLab CI, TeamCity and Azure DevOps as a build step. Results return to the same interface for every team.

Which part of telecom do you run?

Application security challenges in telecom

Challenge

Subscriber data cannot leave the network

Interconnect logic, roaming agreements and network config sit in the same repositories as application code.

Solved

Run every scan inside the network

DerScanner installs on internal servers, air-gapped networks included. Code, findings and the on-prem AI agents stay on premises.

On-premAir-gapped
Challenge

Hundreds of apps, one security team

Portals, apps, billing modules and internal tools ship on separate schedules.

Solved

Scan each release from the CI/CD already in use

Scans start from the pipeline, and tags sort projects by team or product. Findings turn into Azure Boards tasks from the DerScanner interface.

CI/CDProject tagsAzure Boards
Challenge

AI-generated code nobody can trace

Teams cannot tell which commits were written by a human and which by a model.

Solved

Check every commit, whoever wrote it

SAST scans model-written code the same way as human-written code. DerCodeFix proposes fixes for vulnerabilities DerTriage confirmed.

SASTDerCodeFix
Challenge

Alert fatigue eats the queue

Most alerts never get reviewed.

Solved

Clear false positives before human review

DerTriage reviews SAST findings on premises and flags likely false positives before the security team opens the queue.

DerTriageOn-prem AI

How do telecom operators comply with NIS2, TSA and PCI DSS?

Requirement

Article 21 mandates supply chain security as part of risk management. Article 23 sets a 24-hour early warning, a 72-hour notification and a final report within one month.

What DerScanner provides

SCA across the dependency tree with supply chain health scoring. Binary analysis of supplier packages. CVE tracking that links new advisories to the applications carrying the component.

Artifact

CycloneDX SBOM per application and supplier findings report.

Requirement

Article 21 mandates supply chain security as part of risk management. Article 23 sets a 24-hour early warning, a 72-hour notification and a final report within one month.

What DerScanner provides

SCA across the dependency tree with supply chain health scoring. Binary analysis of supplier packages. CVE tracking that links new advisories to the applications carrying the component.

Artifact

CycloneDX SBOM per application and supplier findings report.

Frequently asked questions

Yes. Scanners, database, agents and AI modules install inside the operator network. Licensing loads from a file through the admin panel.

Run a proof of concept on one telecom system

  • Run a proof of concept on one portal or billing module, on internal servers, with results reviewed against the current toolchain.
  • Scan vendor deliverables as binaries, without source code.
  • Export SAST findings mapped to OWASP, CWE, ASVS and MASVS and a CycloneDX SBOM from SCA.

Prefer email? company@derscanner.com