Where Cloud Scanning Is Not a Preference — It Is Prohibited
Handling rules for classified and restricted material rule out security tooling that processes data outside the protected network. That disqualifies SaaS application security entirely. Whitespots is self-hosted by design and deploys inside the zone it protects.
No internet connection required
No live vulnerability feeds, update calls or licence checks. Updates arrive as Docker images, like any other approved software.
Deploys inside the protected zone
A segmented or restricted zone, next to the systems it scans — the platform installs where your architecture allows it, not where a vendor requires it.
Administered by cleared staff
Where the regime requires internal administration of security tooling, an on-premise platform your own people run is the only shape that fits.
Evidence for the accreditation
A dated per-finding record per system, exportable for the authority or prime contractor that has to sign it off.
What Defense Suppliers Run Into
Most application security tooling assumes a network with a route to the vendor. In this segment that assumption is the disqualifier.
The entire SaaS market is out of scope
Once handling rules prohibit analysis outside the protected network, the shortlist is not "which cloud scanner" — it is which platform can run inside.
Two networks, one engineering team
An unclassified development environment and a restricted one, with the same people and often the same components moving between them.
Tools that expect the internet
Many security tools need a live connection for vulnerability feeds, updates or licence checks. In a disconnected network, each of those becomes another exception to accredit.
Requirements from the prime contractor
Requirements arrive through the contract chain. A supplier several tiers down still has to evidence secure development to a standard set elsewhere.
What the Handling Rules Actually Require
The regimes most often cited by defense suppliers, and where each one touches application security tooling.
Requirements for protective software
At the lowest classification tier, malware-detection and analysis software must not perform its scanning outside the protected network — cloud-based analysis is excluded — and the tooling is administered internally.
How Whitespots helps
Self-hosted is the only deployment model that satisfies this, which is why the shortlist in this segment is short. The platform runs inside the network and administers itself from within it.
IT-Grundschutz · building blocks
Documented protection requirements per system, with modules for software development, patch and change management, and vulnerability handling.
How Whitespots helps
Per-system scoping plus a persistent finding history — the evidence layer the building blocks assume already exists.
NIST SP 800-171 · 3.11 and 3.14
Periodic vulnerability scanning of systems and applications, remediation in accordance with risk assessment, and monitoring of security alerts and advisories for controlled unclassified information.
How Whitespots helps
A defined scan cadence, remediation timelines tracked per severity, and an advisory-driven record of what was affected and when.
DEFCON 658 · cyber risk in the supply chain
Suppliers assess cyber risk against the contract's risk profile and flow equivalent requirements down to sub-contractors, with evidence of compliance.
How Whitespots helps
Business criticality is set per product, so each system is scanned according to its own risk profile — including the code your sub-contractors deliver. The platform adds nobody to the chain: it runs isolated inside your infrastructure.
reporting obligations · defence exclusion
From 11 September 2026, manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents; remaining obligations and penalties apply from 11 December 2027. Products developed exclusively for national security or defence purposes are excluded from scope.
How Whitespots helps
Relevant to the dual-use half of a defense supplier's portfolio. Every change is scanned, and each finding records when it first appeared and when it was fixed, so a report can go out inside the window.
Annex A, as listed in BSI's mapping table
Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing in development and acceptance.
How Whitespots helps
Each control maps to an artefact the platform already produces, which is what turns a control statement into audit evidence.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Handling regimes differ by nation and by classification tier, and the row above addresses the lowest German tier specifically — it does not describe higher tiers or other nations. Confirm every requirement with your security officer and the contracting authority.
What Whitespots Gives a Defense Supplier
The deployment model first, because in this segment it is the qualifying criterion rather than a feature.
Qualifies for the protected network, with nothing to exempt
-
Runs air-gapped Segmented, restricted or fully disconnected zones.
-
Only your cleared staff operate it Administered internally.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
Unclassified and restricted networks: one standard, no bridge
-
Same rules on both sides Separate deployments with identical configuration.
-
Updates without a live connection Delivered as Docker images.
-
History for the life of the system Retained per environment.
Pass the prime's requirements down, and prove it
-
Sub-contractor code checked at the gate Quality gates run before handover.
-
Scanning matched to criticality Business criticality set per product.
-
Reports the prime can use For the prime contractor or the authority.
Cleared developers spend their time fixing, not operating tools
-
Developers see the issue on the exact line Findings in the IDE, with remediation guidance.
-
Caught in the pull request Checks run as code is written, not in a pre-delivery scramble.
-
No pipeline rewrite Onboarding through a VCS webhook.
Where It Lands
What a defense supplier's security function is usually asked to produce.
- Scenario
The handling regime rules out cloud analysis
With Whitespots platformA platform that runs entirely inside the protected network.
- Scenario
A prime contractor flows down secure-development requirements
With Whitespots platformAssets split per contract, with reports from the platform you already run.
- Scenario
A disconnected environment needs a platform update
With Whitespots platformNew Docker images brought in like any other approved software, with no outbound connection.
- Scenario
An accreditation asks how findings are managed
With Whitespots platformA dated per-finding record with owners and decisions, exported.
What Defense Teams Ask First
Why does self-hosting matter more here than in other industries?
Because it stops being a preference. Handling rules for restricted material constrain where protective software may process data, and at the German VS-NfD tier that excludes cloud-based scanning outright. Elsewhere self-hosting wins on risk; here it is the entry requirement.
Can it run fully air-gapped?
Yes. The platform is self-hosted with no cloud dependency, sends nothing outward and needs no vulnerability feed from outside. Updates are Docker images, so they reach a closed network the same way as any other approved software. Licence activation is the only step that normally needs a connection, and for disconnected deployments we agree an offline way to do it.
We run an unclassified and a restricted environment. Do we need two deployments?
Usually yes — one per environment, with the same configuration and rules on both. That keeps the standard identical without creating a connection between the two networks.
Does the Cyber Resilience Act apply to us?
Products developed exclusively for national security or defence purposes are outside its scope, but most suppliers also sell dual-use or commercial products that are not. For those, reporting obligations start on 11 September 2026 and the remaining obligations and penalties on 11 December 2027. Confirm the split across your portfolio with your regulatory function.
Who administers the platform?
Your own staff. There is no vendor access path by default, which is what makes the internal-administration requirement satisfiable rather than something to seek an exception for.
A Platform That Can Actually Be Installed Where You Work
Talk to us about a deployment inside a restricted or disconnected network, or start with a free external scan of your unclassified public surface.