The platform layer for application security · Self-hosted
Bring your SAST, DAST, SCA, IaC, custom| scanner. Build one security process.
Scanners dump millions of raw findings. Whitespots deduplicates them, validates, and assigns the rest — inside your own infrastructure.
Whitespots helps you meet these standards — and get certified
- ISO/IEC 27001
- SOC 2
- PCI DSS 4.0
- ISO/IEC 27017
- GDPR
- NIST SSDF
- ISO/IEC 27701
- HIPAA
- OWASP ASVS
- ISO/IEC 27002
- NIS2
- CIS Controls
- ISO/IEC 27034
- DORA
- NIST CSF 2.0
- ISO/IEC 27018
Verification
Findings are validated against your own rules before anyone is asked to act on them.
Deduplication
The same issue reported by four tools becomes one finding with one owner and one history.
Risk rescoring
CVSS recalculated with business context — product criticality, exposure, your own weighting rules.
Prioritization
One consistent order of work across every source, instead of one queue per scanner.
Tasks and ownership
A finding becomes a task with an owner and an SLA clock — Jira natively, or whichever tracker your teams already live in.
Notifications
Any service that accepts a webhook — Slack, Teams, Telegram, your own handler — on criteria and a schedule you set.
Merge request actions
The quality gate comments on the merge request and can close it — filtered by business criticality, severity or verification status.
IDE context
Developers get the finding, its context and its status in the editor they already have open.
LLM-assisted explanations
Plain-language explanation of what a finding means and what a fix looks like — on a self-hosted model by default, or an external provider if you prefer.
- 1
Finding
A connected tool reports an issue.
- 2
Validate
Your rules confirm it is real.
- 3
Deduplicate
Reports of the same issue merge into one.
- 4
Prioritize
Rescored against business context.
- 5
Assign
Gets an owner and an SLA clock.
- 6
Notify
Reaches the channels the team watches.
- 7
Fix
Context lands in the merge request and the IDE.
- 8
Verify
A rescan confirms the fix holds.
- 9
Close
Closed with a full audit trail.
SaaS-only
jit.io and aikido.dev have no full self-hosted option — a hard blocker for regulated buyers, not a line item to negotiate.
+$40k/yr
What ox.security charges as a self-hosted add-on, on top of per-developer licensing. With Whitespots it's included.
€0 premium
Self-hosted is how Whitespots ships by default. Same flat price, unlimited developers, priced per organization.
GitLab Ultimate
Tied to one VCS
you're on GitHub, Bitbucket, Azure DevOps or a mix of VCS providers
$118,800/yr
jit.io
No self-hosting
your data can't leave your infra or you need a real triage workflow
No price fixes it
aikido.dev
No self-hosting
the whole platform must run in your infra, or you're past ~40 developers
€64,800/yr
ox.security
Self-hosting is an add-on
you need real triage, host scans and self-hosted without add-on fees
$140,000/yr
DefectDojo
Self-hosted, but you build it
you want scanning included plus commercial SLAs
~€80,000/yr
Whitespots · €60,000/yr flat, unlimited developers, self-hosted included


