The platform layer for application security · Self-hosted

Bring your SAST, DAST, SCA, IaC, custom| scanner.
Build one security process.

Scanners dump millions of raw findings. Whitespots deduplicates them, validates, and assigns the rest — inside your own infrastructure.

TASK 176K88K304K220K176K
Secrets
SAST
SCA
DAST
Infra
Cloud
Devs get what to fix
Leadership gets metrics
€24k or €60k a year Unlimited developers Self-hosted only

Whitespots helps you meet these standards — and get certified

  • ISO/IEC 27001
  • SOC 2
  • PCI DSS 4.0
  • ISO/IEC 27017
  • GDPR
  • NIST SSDF
  • ISO/IEC 27701
  • HIPAA
  • OWASP ASVS
  • ISO/IEC 27002
  • NIS2
  • CIS Controls
  • ISO/IEC 27034
  • DORA
  • NIST CSF 2.0
  • ISO/IEC 27018
Inside the platform

One queue, one score, one owner — whatever you scan with

Running inside your own infrastructure, the platform turns whatever your tools report into one verified, prioritized backlog — with an owner and a deadline on every item.

aspm.your-company.internal

Your network
Findings list with severity, triage status, SLA and scanner type columns, and the filter panel open on product and business criticality

Every scanner lands in one ordered queue

Filter by product, severity, scanner type, triage status or SLA state — one list to work through, instead of one console per tool.

The platform layer

Your scanners find. The platform runs the process.

Whitespots sits underneath the tools you already run, the way an operating system sits underneath applications. Connect a source once, and everything it reports goes through the same process — every time, whichever tool it came from.

Your infrastructure

Nothing leaves this boundary

Sources you connect

  • SAST
  • DAST
  • SCA
  • Secrets
  • IaC
  • Containers
  • Hosts
  • Cloud
  • API
  • Custom

Whitespots · platform layer

  • Verify
  • Deduplicate
  • Rescore
  • Prioritize
  • Assign
  • Notify
  • Gate
  • Surface
  • Explain

Delivered as work developers already see

  • Jira task
  • MR comment
  • IDE context
  • Webhook alert
  • Dashboard

Findings come in from

25+ scanners ship with the platform, version-pinned

  • Trivy
  • OWASP
  • Snyk
  • SonarQube
  • Checkmarx
  • Qualys
  • Aqua
  • Burp Suite
  • Falco

Work goes out to

Trackers, pipelines, registries, clouds and chat

  • GitHub
  • GitLab
  • Bitbucket
  • Jira
  • Jenkins
  • Docker
  • Kubernetes
  • Terraform
  • Google Cloud
  • Telegram

Not in the list? Point the platform at any scanner's container image and upload one example report — the importer learns the format, and its findings enter the same process as everything else.

Verification

Findings are validated against your own rules before anyone is asked to act on them.

Deduplication

The same issue reported by four tools becomes one finding with one owner and one history.

Risk rescoring

CVSS recalculated with business context — product criticality, exposure, your own weighting rules.

Prioritization

One consistent order of work across every source, instead of one queue per scanner.

Tasks and ownership

A finding becomes a task with an owner and an SLA clock — Jira natively, or whichever tracker your teams already live in.

Notifications

Any service that accepts a webhook — Slack, Teams, Telegram, your own handler — on criteria and a schedule you set.

Merge request actions

The quality gate comments on the merge request and can close it — filtered by business criticality, severity or verification status.

IDE context

Developers get the finding, its context and its status in the editor they already have open.

LLM-assisted explanations

Plain-language explanation of what a finding means and what a fix looks like — on a self-hosted model by default, or an external provider if you prefer.

Custom and internal checks fit too

A commercial tool you already pay for, an internal check your team wrote, a one-off script that knows something about your systems no vendor does — if it produces a JSON report, it fits. Point the platform at the scanner's container image, upload one example report so the importer learns its format, and its findings enter the same process as everything else: verified, deduplicated, scored, assigned.

Configured in the interface — no parser to write and no pipeline code.

Connected by webhook, not by pipeline edits

Sources attach to a whole VCS group at once, so a new repository is covered the day it is created — without a CI template to copy into it.

1

Docker container to deploy

0

CI/CD pipeline edits required

15 sec

To index a full repository pool

From finding to fix

What happens after something is found

Detection is the first step of nine. The other eight are the process — and they run identically whether the finding came from a scanner that ships with the platform or one you connected yourself.

  1. 1

    Finding

    A connected tool reports an issue.

  2. 2

    Validate

    Your rules confirm it is real.

  3. 3

    Deduplicate

    Reports of the same issue merge into one.

  4. 4

    Prioritize

    Rescored against business context.

  5. 5

    Assign

    Gets an owner and an SLA clock.

  6. 6

    Notify

    Reaches the channels the team watches.

  7. 7

    Fix

    Context lands in the merge request and the IDE.

  8. 8

    Verify

    A rescan confirms the fix holds.

  9. 9

    Close

    Closed with a full audit trail.

Sample data

Critical

Hard-coded credential in payment-service

Reported by
3 sources → 1 finding
Business criticality
Payment gateway · 90%
Owner
Platform team
SLA
Resolve in 3 days
Delivered as Jira task MR comment IDE context
Why a scanner is not enough

A scanner finds a problem. It doesn't run your security process.

Good tools are not the issue. The issue is what happens between a tool reporting something and a developer shipping a fix — and that gap is the same whichever scanners you own. Measured lines come from one enterprise rollout, not from a brochure.

Tools without a process layer
The same tools on Whitespots

Blind coverage

5% of repos scanned, the rest live in "known unknowns" for months.

100% repo coverage

Webhooks on the VCS group. Every new repo scans itself from day one.

Measured: ~80 assets/year by hand → 30,000+ connected in 15 minutes

12+ scanners, zero correlation

Every tool is a silo. The same bug appears four times across three reports.

Single pane of glass

Every connected scanner consolidated, deduplicated, scored against business context.

Measured: 1M+ vulnerabilities in one instance, opening in about a second

30% of AppSec time on triage

Senior engineers sort scanner noise instead of fixing real risk.

Triage hours, not days

FP filtering, dynamic CVSS, reachability rules. Devs see only what matters.

Measured: False-positive filtering went from 100% manual to 99% automatic

Scanner changes take weeks

Any tooling change means edits across dozens of pipelines, one repo at a time.

Change once, applies everywhere

Scanner config lives in one place, version-pinned, rolled out centrally.

Measured: Scanner updates: 3–4 weeks → 15 minutes org-wide

Your findings live in a vendor cloud

Every finding, repo name and asset inventory sits on infrastructure you do not control.

Nothing leaves your perimeter

Self-hosted by default — no data-location, data-return or subcontracting questions to answer.

One missing layer

Scanning, orchestration, finding management and developer communication live in different tools that do not talk to each other. That is the layer Whitespots adds — and the reason the tools you already own start to add up.

The process, measured

1.28M findings in. 485 pieces of work out.

The same nine steps, applied at volume: deduplicated, auto-triaged and verified inside your own perimeter before anything reaches a developer.

-99.96% never reach a developer

Sample data

  1. 1,284,930

    Raw scanner findings

  2. 128,493

    After deduplication

    −90.0%
  3. 2,014

    After auto-triage

    −98.4%
  4. 485

    Verified & routed to devs

    −75.9%

Log scale · counts are exact

A process you can report on

Once findings run through one process, the questions leadership asks stop being unanswerable: how much risk is open, against which products, how fast it is closing, and what is past its deadline.

Sample data

AppSec Portal · Dashboard

Current Weighted Risk Trend

Based on Verified and Assigned findings

3.1K▼ -5.2K vs last month
Risk appetite threshold17% of risk appetite
Risk appetite: 18K

Key performance indicators

Unverified
Write more validation rules
41K
findings
Verified
Communicate issues to developers
320
findings
Resolved
You did it!
1.8K
findings

Insights 3

Risk within appetite
-83% below
12 days below threshold
Critical & high findings dropping
▼ 68%
Strong remediation progress this period
Verified findings top CWE
3 CWEs
CWE-79 · CWE-200 · CWE-522

Severity breakdown

Based on Verified and Assigned findings

Critical
8
findings
▼ -13 vs last month
High
36
findings
▼ -52 vs last month
Medium
121
findings
▼ -207 vs last month
Low
108
findings
▼ -175 vs last month
Info
47
findings
▼ -77 vs last month

Scanner breakdown

Based on Verified and Assigned findings

Secrets
6%
of total findings
Critical
2
High
5
Medium
7
Low
4
Info
2
Findings distribution
TOTAL: 20
SAST
38%
of total findings
Critical
2
High
11
Medium
47
Low
42
Info
20
Findings distribution
TOTAL: 122
SCA
31%
of total findings
Critical
3
High
13
Medium
41
Low
31
Info
11
Findings distribution
TOTAL: 99
DAST
12%
of total findings
Critical
1
High
4
Medium
13
Low
14
Info
6
Findings distribution
TOTAL: 38
Infra
8%
of total findings
Critical
0
High
2
Medium
8
Low
10
Info
5
Findings distribution
TOTAL: 25
Cloud
5%
of total findings
Critical
0
High
1
Medium
5
Low
7
Info
3
Findings distribution
TOTAL: 16

Measured at one enterprise rollout

30,000+

assets connected in 15 minutes — up from ~80 a year

99%

of vulnerability validation fully automated

1,000,000+

vulnerabilities handled with sub-1-second load times

15 min

to roll out a scanner update org-wide — down from 3–4 weeks

“Six months ago, we stopped and removed the DevSecOps infrastructure we’d built for a year. Wasted time.”

CISO, iGaming operator

Under constant multi-jurisdiction licensing pressure. Now a Whitespots customer.

Read the case study
One process, two seats

Security gets a process. Developers get less noise.

The same platform layer serves both sides: the people accountable for risk and the people who have to change the code.

For security teams

One process to run, not one queue per tool

  • Every connected source lands in one list of findings
  • Validation rules, risk weighting and policies you define
  • Risk appetite and criticality set per product
  • Manual triage replaced by rules that run on every finding
  • Process metrics you can take into a board or audit conversation

For developers

Work that arrives where the work already happens

  • Fewer findings, because duplicates and noise are filtered first
  • A named owner and a deadline instead of an anonymous report
  • Comments on the merge request being reviewed
  • A quality gate that comments on the merge request — and closes it when policy says so
  • Findings and their context inside the IDE
  • LLM-assisted explanation of what a finding means and how to fix it, on a self-hosted model

Findings in the editor your team already uses

Built for High-Risk Industries

Security Infrastructure for High-Stakes Environments

In these industries a data leak is a licensing problem, not just an incident — which is why every one of these customers needed the findings database to stay on their own infrastructure.

Dedicated guide soon

iGaming

Multi-jurisdiction licensing, mandatory independent audits.

UKGC MGA KSA

Every jurisdiction asks where the data lives. Self-hosted answers all of them the same way.

Our clients: BetBy · Vavada · 01.tech

Dedicated guide soon

Fintech

Payment data, cross-border transfers, third-party risk reviews.

PCI DSS DORA GDPR

"Our data cannot leave the EU" turns most SaaS ASPM into a non-starter.

Our clients: PLATA Bank · Unlimit · INXY · JinglePay

Dedicated guide soon

Telecom

Critical infrastructure under national security scrutiny.

ENISA GSMA

When the regulator audits your security tooling, you need full control of it.

Our clients: Tele2 UZ · Beeline UZ

Dedicated guide soon

Marketplaces & Mobility

Consumer-scale platforms holding payment and location data.

GDPR PCI DSS

Hundreds of repos, thousands of assets, and a breach is a front-page story.

Our clients: inDrive · Xsolla · UZUM Tech

Dedicated guide soon

Healthcare

Patient data protection and strict access controls.

HIPAA GDPR

Patient data cannot be handed to a third-party scanner cloud, at any price.

Our clients: Klaim

Don't See Your Industry?

If auditors, regulators, or data-location requirements shape how you buy software, we've likely solved for it.

Talk to Us
Head-to-Head

Most ASPM Vendors Can't Run in Your Perimeter

Across the ASPM market, self-hosting is either unavailable, partial, or a five-figure add-on. Whitespots ships self-hosted by default, at a flat price, with no on-prem premium. Where each alternative fits, and what it costs at 100 developers.

SaaS-only

jit.io and aikido.dev have no full self-hosted option — a hard blocker for regulated buyers, not a line item to negotiate.

+$40k/yr

What ox.security charges as a self-hosted add-on, on top of per-developer licensing. With Whitespots it's included.

€0 premium

Self-hosted is how Whitespots ships by default. Same flat price, unlimited developers, priced per organization.

Small team? Whitespots has a starter tier at €24,000/yr — under ~50 developers or ~100 assets. TCO figures assume 100 developers, list pricing as of July 2026; negotiated deals may differ.

Pricing

Two Fixed Plans. Fully Self-Hosted.

No per-developer, per-scan, or per-repo billing — no premium for on-prem deployment. Both plans include first-month implementation support.

Online Scanning

For developers

DevSecOps Platform

For enterprise security

Price
€25 NOTHING per report with validated vulnerabilities
€60 000 / year
Setup Time
Immediate
1-2 Days
Best For
Small teams, startups, individual projects
Enterprise, continuous development
Feature Set
  • Repository scanning
  • Domain scanning
  • Automatic validation
  • Detailed reports
  • CI/CD integration
  • Repository scanning
  • Domain scanning
  • Automatic validation
  • Detailed reports
  • CI/CD integration
  • Custom rules
  • Team management
  • SLA support
  • IDE integraions
Included with every plan

First-month implementation support

During the first month of platform usage, Whitespots helps your team set up the key integrations together — no separate professional-services line.

By the end of it you have secret scanning, SAST, DAST, infrastructure checks and cloud security running as one process — without duplicate findings or a separate workflow per tool. That same setup covers most of what regulators ask for in vulnerability management, with an audit trail behind it.

What we set up together

  • Git
  • Quality Gate
  • Jira
  • LLM workflows
  • Notification webhooks
  • Scanner sequence matched to your environment
FAQ

What Security Teams Ask Us First

The questions that come up on every first call with a regulated buyer.

Is Whitespots another scanner?

No. Whitespots is the platform layer that sits underneath the scanners. Scanners ship with it and you can connect your own, but the product is the process that runs afterwards: verification, deduplication, rescoring against business context, prioritization, task creation, notifications, merge request comments and gates, and confirming the fix. ASPM here means application security posture management — managing findings and the process around them. It is not RASP, which protects an application at runtime.

Where does our vulnerability data live?

Entirely on your infrastructure. The platform deploys as a single Docker or Kubernetes workload inside your perimeter, and the findings database never leaves it. No vendor cloud, no subcontracting chain, no data-return questions when a contract ends.

Can we run it air-gapped?

Yes. The platform is built for fully on-prem operation — network access is needed only for license activation. It has been tested at 10M+ findings on a single self-hosted instance.

Do we have to change our CI/CD pipelines?

No. Whitespots watches your GitLab, GitHub or Bitbucket groups via a webhook — every new repository gets scanned on creation, and a full repo pool is indexed in about 15 seconds. No CI templates to copy, no allow_failure fights with developers.

Which scanners are included — and can we bring our own?

Scanners for SAST, DAST, SCA, secrets, IaC, container, host, cloud and API checks ship out of the box, all version-pinned so four teams never run four different versions of the same tool. Anything else fits too: if a scanner produces a JSON report, you point the platform at its container image and upload one example report so the importer learns the format. No parser to write, no pipeline code.

How is it priced?

Two flat plans per organization: €24,000/year (Startup — under ~50 developers or ~100 assets) and €60,000/year (Enterprise — unlimited assets, 24/7 critical support). No per-developer, per-scan or per-repo billing, and no premium for self-hosted deployment. Both plans include first-month implementation support.

What happens if we decide to leave?

Exit is trivial: the platform and all of its data were always running on your infrastructure, so there is nothing to export from a vendor cloud and no data-deletion attestations to chase. Your findings history stays with you.

About Us

Built by Security Experts, for Security Experts

At Whitespots.io, we believe security software should be self-hosted, transparent, and fully controlled by the organizations that use it. That’s why we’re building tools for people like us—security professionals who understand the stakes.

Open and Public

We are open to conferences, meetups, public and private topics.

Trusted by Application Security Teams

Leading security teams rely on Whitespots.io because they demand full control, transparency, and tools that meet their standards — not marketing crap.

Proven by Results, not Just Promises

Millions processed vulnerabilities result into hundreds of unique issues without any dev headache.

Conference workshop
Conference speaking
Conference presentation
Conference networking
Conference workshop
Conference speaking
Feedback

Trusted by Security Professionals

Here's what our clients say about our services

5.0

Using Application Security portal was a breath of fresh air after moving from Defect Dojo. The guys follow an agile approach with stable releases and adding new features.

avatar

Sergey Nozhenko

Information Security Engineer

5.0

Use the Application Security portal for automating the continuous vulnerability assessment and defect management processes. It helps a lot to work with reports from various scanning tools, specifically when working with noisy reports and false positives. Auto-validators and deduplicators work well. It really helps to reduce the operational cost of the process. As a results, we have quite a tiny, pretty-looking and relevant backlog to discuss with the product teams.

avatar

Anatoli M

CSO

5.0

Recently tried this new security platform and I'm liking it. It's easy to use and great for handling vulnerabilities in app development. A solid choice for anyone in security.

avatar

Dmitry Donchenko

data scientist, co-founder

Build the process around the tools you already have

Connect your scanners, run one process, and turn every finding into work with an owner — on infrastructure you control, at a flat price.

Contact

Get in Touch With Our Team

Have questions about our services or need a custom solution? Reach out to us and we'll get back to you promptly.

Schedule a consultation with a Whitespots expert now!

Demo
Please write a few sentences

By sending the message, you agree with our Terms of use and Privacy Policy