Software That Moves People Is Audited Like It
Ride-hailing apps, fleet backends and vehicle software all carry location data and, increasingly, type-approval obligations. Whitespots covers the whole chain — app, backend and embedded — in one findings database you host yourself.
App, backend and vehicle in one model
Mobile clients, fleet services and embedded software produce findings in the same database instead of three disconnected programmes.
Location data never leaves
Trip histories and live positions are among the most sensitive datasets a consumer platform holds. The scanner that reads that code runs on your infrastructure.
Evidence for your CSMS audit
A cybersecurity management system is audited on its records. The platform keeps them as you work: what was found, what was decided and when it was fixed.
Supplier software checked too
Most vehicle and fleet software comes from suppliers, but the risk stays with you. Delivered code goes through your quality gates, and domain, host and cloud scans check where it runs.
What Mobility Engineering Teams Run Into
Mobility spans a consumer app shipping weekly and vehicle software that has to hold a type approval for years — with the same organisation answerable for both.
Three release cadences, one risk picture
Weekly app releases, continuous backend deploys and vehicle software on a homologation cycle rarely share a security process, and the risk view suffers for it.
Type approval depends on process evidence
Authorities approve a management system, not a scan result. Without records that prove the process runs, a new vehicle type is not approved for the market, however few vulnerabilities it has.
Long-lived software, long-lived exposure
A vehicle stays on the road far longer than a service stays in support, and the component you shipped years ago is still yours to monitor.
Location data at consumer scale
A breach here exposes where people were and when. That raises both the regulatory and the reputational cost above ordinary consumer data.
What the Frameworks Actually Require
The obligations that reach mobility software, from vehicle type approval to consumer data protection.
Cyber Security Management System
Manufacturers demonstrate a certified CSMS covering risk identification, assessment and treatment across development, production and post-production, including monitoring for new threats and vulnerabilities.
How Whitespots helps
Continuous vulnerability monitoring with a dated per-finding record across all three phases, exportable as CSMS evidence rather than reconstructed for an audit.
Software Update Management System
A documented system for managing software updates, including identification of affected vehicle types and records of software versions and their integrity.
How Whitespots helps
Dependencies scanned on every commit, so a vulnerable component is found as soon as it enters the code rather than during an investigation.
Road vehicles · cybersecurity engineering
Cybersecurity activities across the lifecycle, including vulnerability analysis and management, with work products retained as evidence.
How Whitespots helps
A complete trail and regular reports: findings, decisions, owners and closure dates kept in one record.
Transport sector · risk-management measures
Where an operator falls in scope, measures must include vulnerability handling and disclosure, supply-chain security, and incident reporting within defined deadlines.
How Whitespots helps
Every change is scanned, with automatic validation and deduplication. Configurable notifications and per-severity SLAs let the right people act in time to meet reporting and fixing deadlines, including a 24-hour early warning.
Articles 5 and 32
Location and trip data must be minimised and protected, with technical measures regularly tested, assessed and evaluated.
How Whitespots helps
Continuous testing on infrastructure inside your own perimeter, so trip data never becomes a security vendor's processing activity.
Products with digital elements
Reporting of actively exploited vulnerabilities from 11 September 2026; remaining obligations and penalties from 11 December 2027. Vehicles type-approved under the relevant EU framework are addressed separately from the general regime.
How Whitespots helps
Relevant to connected accessories, fleet hardware and companion apps outside vehicle type approval. Continuous scanning surfaces vulnerabilities early, and each finding records when it appeared and when it was fixed — the facts a report needs.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. UN R155/R156 apply through national type-approval authorities and their scope depends on vehicle category; CRA interaction with vehicle type approval is handled by sector-specific provisions. Confirm applicability with your homologation and regulatory functions.
What Whitespots Gives a Mobility Security Team
One programme spanning a weekly app release and a vehicle component with a decade of service life.
Trip and fleet data, and the way to reach them, stay inside
-
Sits beside restricted build systems Deployable in restricted networks.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
Mobile, backend and embedded code in one view, the way incidents move
-
Embedded toolchains covered Custom and in-house scanners.
-
Dependencies checked on every commit Container images too.
-
One flaw is one finding Deduplicated across every scanner.
Post-production monitoring evidence that holds for years
-
Know when each issue appeared and closed Per-finding trail of scanner, severity and every decision.
-
Pentests in the same record Manual findings imported alongside scanner output.
-
Ready for approval audits Exportable evidence for approval authorities.
Supplier code meets your bar before it ships in your product
-
Rejected before integration Acceptance criteria enforced as quality gates.
-
Scanned where it runs Domain, host and cloud scans for supplier software.
-
One record for your code and theirs Assets split by supplier or component.
Where It Lands
What a mobility security function is usually asked to produce.
- Scenario
An approval authority audits the management system
With Whitespots platformContinuous records across development, production and post-production, exported.
- Scenario
A vulnerable component ships in a released build
With Whitespots platformEvery affected system identified, with the date each finding first appeared.
- Scenario
A supplier delivers integration software
With Whitespots platformChecked against your quality gates, then scanned where it runs.
- Scenario
An incident starts a reporting clock
With Whitespots platformWhat was known about the affected systems, and when, without archaeology.
Already Running in Mobility
Large ride-hailing and mobility platforms run the platform self-hosted across app, backend and infrastructure code. Names are withheld here pending each customer's sign-off.
Global ride-hailing platform
Covers mobile clients and backend services in one findings database, with ownership routed to service teams.
What Mobility & Transportation Teams Ask First
Does this cover embedded and vehicle software, or only web and mobile?
The platform is the findings database and the workflow around whichever scanners reach your code. Embedded toolchains usually mean niche or in-house analysers; their output is imported into the same model as everything else, which is the point — one risk picture rather than three.
Will this get us a UN R155 approval?
No tool grants an approval. R155 is assessed against your cybersecurity management system, and what the platform contributes is the evidence layer that system runs on: continuous monitoring, dated findings, recorded decisions and retained work products across all three lifecycle phases.
Our vehicle software has a ten-year service life. Does the record last?
The findings database is yours and stays on your infrastructure, so retention is a matter of your own policy rather than a vendor's contract term. That is a practical argument for self-hosting in this sector specifically.
Most of our components come from suppliers. What can we actually do?
Check each delivery against your quality gates before integration, and scan the domains, hosts and cloud where the software runs. Supplier findings go into the same record as your own. You cannot patch their code, but you can show that you found, escalated and managed each issue — which is what the audit asks.
Why does self-hosting matter for a consumer mobility app?
Because the data is location. A scanner cloud holding your source code and unfixed findings is a map of how to reach where your users have been, and it is one more organisation whose breach becomes your notification.
One Risk Picture From App to Vehicle
Start with a free external scan of your public surface, or talk to us about a self-hosted deployment covering app, backend and embedded software.