Industry Mobility, automotive & transport

Software That Moves People Is Audited Like It

Ride-hailing apps, fleet backends and vehicle software all carry location data and, increasingly, type-approval obligations. Whitespots covers the whole chain — app, backend and embedded — in one findings database you host yourself.

App, backend and vehicle in one model

Mobile clients, fleet services and embedded software produce findings in the same database instead of three disconnected programmes.

Location data never leaves

Trip histories and live positions are among the most sensitive datasets a consumer platform holds. The scanner that reads that code runs on your infrastructure.

Evidence for your CSMS audit

A cybersecurity management system is audited on its records. The platform keeps them as you work: what was found, what was decided and when it was fixed.

Supplier software checked too

Most vehicle and fleet software comes from suppliers, but the risk stays with you. Delivered code goes through your quality gates, and domain, host and cloud scans check where it runs.

Key challenges

What Mobility Engineering Teams Run Into

Mobility spans a consumer app shipping weekly and vehicle software that has to hold a type approval for years — with the same organisation answerable for both.

Three release cadences, one risk picture

Weekly app releases, continuous backend deploys and vehicle software on a homologation cycle rarely share a security process, and the risk view suffers for it.

Type approval depends on process evidence

Authorities approve a management system, not a scan result. Without records that prove the process runs, a new vehicle type is not approved for the market, however few vulnerabilities it has.

Long-lived software, long-lived exposure

A vehicle stays on the road far longer than a service stays in support, and the component you shipped years ago is still yours to monitor.

Location data at consumer scale

A breach here exposes where people were and when. That raises both the regulatory and the reputational cost above ordinary consumer data.

Clause map

What the Frameworks Actually Require

The obligations that reach mobility software, from vehicle type approval to consumer data protection.

UN Regulation No. 155 UNECE

Cyber Security Management System

Manufacturers demonstrate a certified CSMS covering risk identification, assessment and treatment across development, production and post-production, including monitoring for new threats and vulnerabilities.

How Whitespots helps

Continuous vulnerability monitoring with a dated per-finding record across all three phases, exportable as CSMS evidence rather than reconstructed for an audit.

UN Regulation No. 156 UNECE

Software Update Management System

A documented system for managing software updates, including identification of affected vehicle types and records of software versions and their integrity.

How Whitespots helps

Dependencies scanned on every commit, so a vulnerable component is found as soon as it enters the code rather than during an investigation.

ISO/SAE 21434 International

Road vehicles · cybersecurity engineering

Cybersecurity activities across the lifecycle, including vulnerability analysis and management, with work products retained as evidence.

How Whitespots helps

A complete trail and regular reports: findings, decisions, owners and closure dates kept in one record.

NIS2 European Union

Transport sector · risk-management measures

Where an operator falls in scope, measures must include vulnerability handling and disclosure, supply-chain security, and incident reporting within defined deadlines.

How Whitespots helps

Every change is scanned, with automatic validation and deduplication. Configurable notifications and per-severity SLAs let the right people act in time to meet reporting and fixing deadlines, including a 24-hour early warning.

GDPR European Union

Articles 5 and 32

Location and trip data must be minimised and protected, with technical measures regularly tested, assessed and evaluated.

How Whitespots helps

Continuous testing on infrastructure inside your own perimeter, so trip data never becomes a security vendor's processing activity.

Cyber Resilience Act European Union

Products with digital elements

Reporting of actively exploited vulnerabilities from 11 September 2026; remaining obligations and penalties from 11 December 2027. Vehicles type-approved under the relevant EU framework are addressed separately from the general regime.

How Whitespots helps

Relevant to connected accessories, fleet hardware and companion apps outside vehicle type approval. Continuous scanning surfaces vulnerabilities early, and each finding records when it appeared and when it was fixed — the facts a report needs.

References reflect published text as of August 2026 and describe obligations rather than a certification we grant. UN R155/R156 apply through national type-approval authorities and their scope depends on vehicle category; CRA interaction with vehicle type approval is handled by sector-specific provisions. Confirm applicability with your homologation and regulatory functions.

Platform

What Whitespots Gives a Mobility Security Team

One programme spanning a weekly app release and a vehicle component with a decade of service life.

Self-hosted 01

Trip and fleet data, and the way to reach them, stay inside

  • Sits beside restricted build systems Deployable in restricted networks.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

  • Leave whenever you want Exit is a database export, not a vendor negotiation.

See deployment options →
End-to-end coverage 02

Mobile, backend and embedded code in one view, the way incidents move

  • Embedded toolchains covered Custom and in-house scanners.

  • Dependencies checked on every commit Container images too.

  • One flaw is one finding Deduplicated across every scanner.

Explore the platform →
Long-term records 03

Post-production monitoring evidence that holds for years

  • Know when each issue appeared and closed Per-finding trail of scanner, severity and every decision.

  • Pentests in the same record Manual findings imported alongside scanner output.

  • Ready for approval audits Exportable evidence for approval authorities.

How it works →
Supplier software 04

Supplier code meets your bar before it ships in your product

  • Rejected before integration Acceptance criteria enforced as quality gates.

  • Scanned where it runs Domain, host and cloud scans for supplier software.

  • One record for your code and theirs Assets split by supplier or component.

See the platform tiers →
Outcomes

Where It Lands

What a mobility security function is usually asked to produce.

  • Scenario

    An approval authority audits the management system

    With Whitespots platform

    Continuous records across development, production and post-production, exported.

  • Scenario

    A vulnerable component ships in a released build

    With Whitespots platform

    Every affected system identified, with the date each finding first appeared.

  • Scenario

    A supplier delivers integration software

    With Whitespots platform

    Checked against your quality gates, then scanned where it runs.

  • Scenario

    An incident starts a reporting clock

    With Whitespots platform

    What was known about the affected systems, and when, without archaeology.

Proof

Already Running in Mobility

Large ride-hailing and mobility platforms run the platform self-hosted across app, backend and infrastructure code. Names are withheld here pending each customer's sign-off.

Global ride-hailing platform

Covers mobile clients and backend services in one findings database, with ownership routed to service teams.

FAQ

What Mobility & Transportation Teams Ask First

Does this cover embedded and vehicle software, or only web and mobile?

The platform is the findings database and the workflow around whichever scanners reach your code. Embedded toolchains usually mean niche or in-house analysers; their output is imported into the same model as everything else, which is the point — one risk picture rather than three.

Will this get us a UN R155 approval?

No tool grants an approval. R155 is assessed against your cybersecurity management system, and what the platform contributes is the evidence layer that system runs on: continuous monitoring, dated findings, recorded decisions and retained work products across all three lifecycle phases.

Our vehicle software has a ten-year service life. Does the record last?

The findings database is yours and stays on your infrastructure, so retention is a matter of your own policy rather than a vendor's contract term. That is a practical argument for self-hosting in this sector specifically.

Most of our components come from suppliers. What can we actually do?

Check each delivery against your quality gates before integration, and scan the domains, hosts and cloud where the software runs. Supplier findings go into the same record as your own. You cannot patch their code, but you can show that you found, escalated and managed each issue — which is what the audit asks.

Why does self-hosting matter for a consumer mobility app?

Because the data is location. A scanner cloud holding your source code and unfixed findings is a map of how to reach where your users have been, and it is one more organisation whose breach becomes your notification.

One Risk Picture From App to Vehicle

Start with a free external scan of your public surface, or talk to us about a self-hosted deployment covering app, backend and embedded software.